Google reCAPTCHA集成验证阶段多问题求助(PHP方法疑问+REST API调用报错)
Google reCAPTCHA集成验证阶段多问题求助(PHP方法疑问+REST API调用报错)
看起来你在集成Google reCAPTCHA Enterprise的时候卡在了验证环节,我来逐个拆解你的疑问,再结合你给出的代码给出具体的修改建议:
一、关于require 'vendor/autoload.php';的含义
这行代码是PHP的Composer依赖管理工具生成的自动加载文件。Google reCAPTCHA的官方PHP SDK是通过Composer安装的,这个文件的作用是自动加载你通过Composer安装的所有第三方类库(包括reCAPTCHA的SDK),不用你手动一个个引入零散的类文件。
如果你还没接触过Composer,有两种选择:
- 先安装Composer,再执行
composer require google/cloud-recaptcha-enterprise安装SDK,之后就能正常使用这行代码; - 跳过SDK,直接用原生PHP发送POST请求验证token(下面会给出这种方案的代码,更适合新手快速上手,不用折腾依赖)。
二、验证reCAPTCHA的PHP代码该放哪里?
你的表单是通过action="submit-form.php"提交的,所以所有reCAPTCHA验证逻辑必须放在submit-form.php的最开头——也就是在处理表单数据(比如获取公司名、联系人等字段)之前,先验证token是否有效。只有验证通过了,再继续执行后续的业务逻辑(比如存数据库、发邮件等)。
三、REST API浏览器访问报错的原因
你直接在浏览器输入API URL会报错,核心有两个原因:
- Google reCAPTCHA Enterprise的API要求用POST方法发送请求,但浏览器直接输入URL是发送GET请求,完全不符合API的请求方式要求;
- 这个API绝对不能在前端(浏览器)直接调用,必须在后端服务(比如你的
submit-form.php)里发起请求,否则你的API密钥会直接暴露,带来安全风险。
所以别在浏览器里试这个URL了,把请求逻辑写在后端代码里才是正确的做法。
结合你的现有代码,具体修改方案
1. 修复HTML表单的两处问题
你的现有HTML有两个明显的bug:
- 表单没有
id属性,但你的onSubmit函数里用了document.getElementById("demo-form"),需要给表单加上id="gtld"(和表单name保持一致); - 重复写了一次g-recaptcha按钮,需要删除重复的那一行。
修改后的完整HTML表单代码:
<form action="submit-form.php" method="POST" class="space-y-4" name="gtld" id="gtld"> <input type="text" name="company" placeholder="Company Name" required class="w-full p-3 border border-gray-300 rounded" /> <input type="text" name="contact" placeholder="Contact Person" required class="w-full p-3 border border-gray-300 rounded" /> <input type="url" name="website" placeholder="Website" required class="w-full p-3 border border-gray-300 rounded" /> <fieldset class="border p-4 rounded"> <legend class="text-lg font-medium">Services Offered</legend> <div class="space-y-2 mt-2"> <label class="block"><input type="checkbox" name="services[]" value="Application writing and submission" /> Application writing and submission</label> <label class="block"><input type="checkbox" name="services[]" value="Provide advice and identify resources" /> Provide advice and identify resources</label> <label class="block"><input type="checkbox" name="services[]" value="Legal services" /> Legal services</label> <label class="block"><input type="checkbox" name="services[]" value="Backend Registry provider" /> Backend Registry provider</label> </div> </fieldset> <textarea name="about" maxlength="300" placeholder="About the Company (max 300 characters)" class="w-full p-3 border border-gray-300 rounded" required></textarea> <button class="g-recaptcha" data-sitekey="8LcIiKwrAAAAAPyi7EBe1oNCmVORx_SYxdLVpAtk" data-callback='onSubmit' data-action='submit'> Submit </button> </form> <!-- 保留reCAPTCHA官方脚本 --> <script src="https://www.google.com/recaptcha/api.js"></script> <script> function onSubmit(token) { document.getElementById("gtld").submit(); // 这里改成你的表单id } </script>
2. submit-form.php中的验证代码(原生PHP,无需Composer)
下面是不需要安装任何依赖的原生PHP验证代码,直接放在submit-form.php的最开头即可:
<?php // 1. 获取表单提交的reCAPTCHA token $recaptchaToken = $_POST['g-recaptcha-response'] ?? ''; if (empty($recaptchaToken)) { die("请完成reCAPTCHA人机验证"); } // 2. 配置你的reCAPTCHA核心信息 $secretKey = "你的reCAPTCHA私钥"; // 注意:这是私钥,绝对不能暴露给前端! $siteKey = "8LcIiKwrAAAAAPyi7EBe1oNCmVORx_SYxdLVpAtk"; // 你的站点公钥 $apiUrl = "https://recaptchaenterprise.googleapis.com/v1/projects/annuaire-1755692338178/assessments?key=你的API密钥"; // 3. 准备要发送给Google的JSON数据 $postData = json_encode([ "event" => [ "token" => $recaptchaToken, "expectedAction" => "submit", // 必须和按钮上的data-action值一致 "siteKey" => $siteKey ] ]); // 4. 发送POST请求到Google验证API $ch = curl_init($apiUrl); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $postData); curl_setopt($ch, CURLOPT_HTTPHEADER, ['Content-Type: application/json']); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $response = curl_exec($ch); curl_close($ch); // 5. 解析响应结果,判断验证是否通过 $responseData = json_decode($response, true); // 分数范围0-1,分数越高越可能是真人,可根据需求调整阈值(比如0.5) if (!$responseData || $responseData['riskAnalysis']['score'] < 0.5) { die("人机验证失败,请重试"); } // 6. 验证通过,开始处理你的表单业务逻辑 $company = $_POST['company'] ?? ''; $contact = $_POST['contact'] ?? ''; $website = $_POST['website'] ?? ''; $services = $_POST['services'] ?? []; $about = $_POST['about'] ?? ''; // 这里写你的业务代码,比如发送邮件、存入数据库等 // ... echo "表单提交成功!"; ?>
注意:
- 替换代码中的
你的reCAPTCHA私钥和你的API密钥为你在Google控制台获取的对应密钥; riskAnalysis.score是Google返回的风险评分,0-1之间,你可以根据业务需求调整阈值(比如把0.5改成0.6,提高验证严格度)。
如果后续你想尝试Composer+SDK的方式,步骤很简单:
- 安装Composer(官网下载对应系统的安装包);
- 在项目根目录执行
composer require google/cloud-recaptcha-enterprise; - 在
submit-form.php开头加上require 'vendor/autoload.php';,再按照Google官方文档的SDK示例编写验证代码即可。
内容来源于stack exchange
相关产品推荐
相关产品推荐

