网站集成Recaptcha V3遇invalid-input-response错误求助
解决Recaptcha V3 invalid-input-response错误的方案
先梳理你代码里的核心问题,对应给出修复步骤:
1. Site Key不匹配
你的前端代码里用了两个不同的Recaptcha Site Key:
- index.php加载api.js时用的是:
6LexkIoiAAAAAGxENEyPQ-e5sVubBaKlX9HSVM31 - index.js调用
grecaptcha.execute时用的是:6LdLk7EUAAAAAEWHuB2tabMmlxQ2-RRTLPHEGe9Y
这两个必须完全一致,替换成你在Google Recaptcha控制台获取的V3 Site Key。
2. Secret Key未替换
captchahandler.php里的RECAPTCHA_V3_SECRET_KEY是占位符my-secret-key,必须替换成控制台对应的V3 Secret Key,Site Key和Secret Key要一一对应。
3. 冗余代码干扰
- index.php里重复了
</head>标签,删掉其中一个,保证HTML结构正确。 - submit按钮的
onclick="prnt()"函数未定义,会触发报错,直接删除该属性。
4. 优化前端提交逻辑
当前JS每次提交会重复添加隐藏字段,可优化为更可靠的方式:
$('#getkeyForm').submit(function(event) { event.preventDefault(); const $form = $(this); grecaptcha.ready(function() { grecaptcha.execute('你的V3 Site Key', {action: 'getkey'}).then(function(token) { // 先移除旧字段,避免重复提交 $form.find('input[name="token"], input[name="action"]').remove(); $form.append(`<input type="hidden" name="token" value="${token}">`); $form.append(`<input type="hidden" name="action" value="getkey">`); $form.unbind('submit').submit(); }); }); });
5. 后端验证补充
在captchahandler.php里增加参数检查和错误排查:
<?php define("RECAPTCHA_V3_SECRET_KEY", '你的V3 Secret Key'); // 先检查参数是否存在 if(!isset($_POST['token']) || !isset($_POST['action'])) { echo 'FAIL: Missing token or action'; exit; } $token = $_POST['token']; $action = $_POST['action']; // 发起验证请求 $ch = curl_init(); curl_setopt($ch, CURLOPT_URL,"https://www.google.com/recaptcha/api/siteverify"); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query([ 'secret' => RECAPTCHA_V3_SECRET_KEY, 'response' => $token, 'remoteip' => $_SERVER['REMOTE_ADDR'] // 添加用户IP提升验证准确性 ])); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // 本地测试可临时禁用SSL验证,生产环境建议开启 curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); $response = curl_exec($ch); // 检查curl请求是否失败 if(curl_errno($ch)) { echo 'FAIL: Curl error - '.curl_error($ch); curl_close($ch); exit; } curl_close($ch); $arrResponse = json_decode($response, true); if(!$arrResponse) { echo 'FAIL: Invalid JSON response'; exit; } // 验证响应结果 if($arrResponse["success"] && $arrResponse["action"] === $action && $arrResponse["score"] >= 0.5) { echo 'SUCCESS'; print_r($arrResponse); } else { echo 'FAIL'; // 打印错误代码便于排查 if(isset($arrResponse['error-codes'])) { echo '<br>Error codes: '.implode(', ', $arrResponse['error-codes']); } print_r($arrResponse); } ?>
额外检查项
- 确保你的域名(含localhost)已添加到Google Recaptcha控制台的域名列表中。
- 检查服务器是否允许curl访问外部域名,部分服务器会屏蔽外部请求。
- 确认创建的是Recaptcha V3密钥对,V2和V3密钥不通用。
内容的提问来源于stack exchange,提问作者nnaem
相关产品推荐
相关产品推荐

