You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

向reCAPTCHA服务器发送POST请求验证令牌时获异常响应

问题原因及解决方案

你的请求返回不透明响应(status:0、type:opaque),核心问题有两个:

1. 错误启用mode: 'no-cors'

no-cors是前端浏览器跨域场景下的特殊模式,启用后浏览器会刻意隐藏响应内容,只返回不透明的Response对象。后端服务(Meteor.js)不存在浏览器跨域限制,完全不需要设置这个参数,直接删除即可。

2. 请求体格式与Content-Type不匹配

你设置了Content-Type: application/x-www-form-urlencoded,但请求体用JSON.stringify生成了JSON格式字符串,这和reCAPTCHA要求的表单编码格式不符。需要将请求体改为键值对拼接的表单格式。

修正后的代码

async function determineVulnerability(token) {
    const SECRET_KEY = '<SECRET_KEY>';
    const url = 'https://www.google.com/recaptcha/api/siteverify';
    
    try {   
        const settings = {
            method: 'POST',
            headers: { 
                'Content-Type': 'application/x-www-form-urlencoded; charset=utf-8',
            },
            body: new URLSearchParams({
                secret: SECRET_KEY,
                response: token,
            }).toString(),
        };

        const apiResponse = await fetch(url, settings);
        // 解析响应为JSON格式,才能获取验证得分等数据
        const verificationResult = await apiResponse.json();
        return verificationResult;

    } catch (e) {
        console.error(e);
    }
}

额外说明

  • 用URLSearchParams可以自动处理参数编码,避免手动拼接时出现字符转义问题。
  • 必须解析响应为JSON(await apiResponse.json()),否则仅能拿到Response对象,无法直接获取验证结果里的score字段。

内容的提问来源于stack exchange,提问作者Subigya Gautam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 00:21:26