You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CodeIgniter中ReCAPTCHA报MISSING-INPUT-RESPONSE错误求排查

Fixing "MISSING-INPUT-RESPONSE" Error in CodeIgniter reCAPTCHA Validation

Problem Description

I implemented reCAPTCHA validation for a form in CodeIgniter, and here's my controller validation function:

public function validate_captcha() { 
    $recaptcha = trim($this->input->post('g-recaptcha-response')); 
    $userIp= $this->input->ip_address(); 
    $secret='6LcuEP4UAAAAAGa1zwXxGTV0r1fNHMZqnTGeN-c_'; 
    $secretdata = array( 
        'secret' => "$secret", 
        'response' => "$recaptcha", 
        'remoteip' =>"$userIp" 
    ); 
    $verify = curl_init(); 
    curl_setopt($verify, CURLOPT_URL, "https://www.google.com/recaptcha/api/siteverify"); 
    curl_setopt($verify, CURLOPT_POST, true); 
    curl_setopt($verify, CURLOPT_POSTFIELDS, http_build_query($secretdata)); 
    curl_setopt($verify, CURLOPT_SSL_VERIFYPEER, false); 
    curl_setopt($verify, CURLOPT_RETURNTRANSFER, true); 
    $response = curl_exec($verify); 
    $status= json_decode($response, true); 
    if(empty($status['success'])){ 
        return FALSE; 
    }else{ 
        return TRUE; 
    } 
}

Currently, this function returns the error: {"SUCCESS":FALSE,"ERROR-CODES":["MISSING-INPUT-RESPONSE"]}. I need help troubleshooting this issue.


Troubleshooting & Solutions

The MISSING-INPUT-RESPONSE error means Google's reCAPTCHA service isn't receiving the g-recaptcha-response value from your frontend. Let's break down the fixes step by step:

1. Verify Frontend Implementation First

This is the most common cause of this error:

  • Ensure you've loaded the reCAPTCHA script correctly in your frontend HTML:
    <script src="https://www.google.com/recaptcha/api.js" async defer></script>
    
  • Double-check the reCAPTCHA container has the correct site key (matches your backend secret key's paired site key):
    <div class="g-recaptcha" data-sitekey="YOUR_SITE_KEY_HERE"></div>
    
  • Confirm the form uses POST method and the g-recaptcha-response field isn't being cleared by custom JS before submission. Test this by running document.querySelector('[name="g-recaptcha-response"]').value in your browser's console right before submitting the form—this should return a long string, not an empty value.

2. Check CodeIgniter Input Filtering

CodeIgniter's input sanitization might be blocking the response value:

  • Open application/config/config.php and check if $config['global_xss_filtering'] is enabled. If it is, try disabling it temporarily (or add g-recaptcha-response to a whitelist if you need global filtering on).
  • Test using raw PHP superglobals instead of CodeIgniter's input class to rule out filtering issues:
    $recaptcha = trim($_POST['g-recaptcha-response'] ?? '');
    

3. Optimize Your Validation Function

Your code has a few areas to fix and improve:

  • Never disable SSL verification: Removing CURLOPT_SSL_VERIFYPEER = false is critical for security—this exposes your request to man-in-the-middle attacks.
  • Add early empty value check: Avoid unnecessary API calls if the reCAPTCHA response is empty.
  • Handle cURL errors: Add checks to catch issues with the API request itself.

Here's the revised function:

public function validate_captcha() { 
    $recaptcha = trim($this->input->post('g-recaptcha-response') ?? ''); 
    
    // Early exit if response is empty
    if(empty($recaptcha)){
        return FALSE;
    }

    $userIp= $this->input->ip_address(); 
    $secret='6LcuEP4UAAAAAGa1zwXxGTV0r1fNHMZqnTGeN-c_'; 
    $secretdata = array( 
        'secret' => $secret, 
        'response' => $recaptcha, 
        'remoteip' => $userIp 
    ); 

    $verify = curl_init(); 
    curl_setopt($verify, CURLOPT_URL, "https://www.google.com/recaptcha/api/siteverify"); 
    curl_setopt($verify, CURLOPT_POST, true); 
    curl_setopt($verify, CURLOPT_POSTFIELDS, http_build_query($secretdata)); 
    curl_setopt($verify, CURLOPT_RETURNTRANSFER, true); 
    
    $response = curl_exec($verify); 

    // Check for cURL errors
    if(curl_errno($verify)){
        // Log the error here if needed
        curl_close($verify);
        return FALSE;
    }

    curl_close($verify);
    $status= json_decode($response, true); 

    return !empty($status['success']); 
}

4. Test the API Directly

If you confirm the frontend is sending the g-recaptcha-response value, test the Google API manually using Postman or curl with your secret key, the response value from the frontend, and your IP address. This will confirm if the issue is with your CodeIgniter code or the API communication.


内容的提问来源于stack exchange,提问作者user13570702

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 19:47:31