如何在含reCaptcha的三页面架构中实现PHP页面间跳转?含未公开步骤
完整实现reCaptcha v2验证(HTML + 双PHP页面方案)
刚折腾完一套带reCaptcha的表单验证流程,把所有细节(包括很多回答没提到的踩坑点)整理出来,正好对应你说的1个HTML页+2个PHP页的场景,直接抄改就能用!
一、HTML表单页面(比如命名为form.html)
这是用户填写信息并触发reCaptcha的页面,核心是要正确引入Google的reCaptcha脚本,并且把验证组件放到表单里:
<!DOCTYPE html> <html> <head> <title>带reCaptcha的表单</title> <!-- 引入reCaptcha v2脚本,替换成你自己的site key --> <script src="https://www.google.com/recaptcha/api.js" async defer></script> </head> <body> <!-- 如果有验证失败的错误提示,这里通过GET参数显示 --> <?php if(isset($_GET['error']) && $_GET['error'] == 'bot'): ?> <p style="color:red;">你是机器人!请重试!</p> <?php endif; ?> <form action="verify.php" method="POST"> <label for="name">姓名:</label> <input type="text" id="name" name="name" value="<?php echo isset($_GET['name']) ? htmlspecialchars($_GET['name']) : ''; ?>" required><br> <label for="email">邮箱:</label> <input type="email" id="email" name="email" value="<?php echo isset($_GET['email']) ? htmlspecialchars($_GET['email']) : ''; ?>" required><br> <!-- reCaptcha验证组件,替换成你的site key --> <div class="g-recaptcha" data-sitekey="你的Site Key"></div><br> <button type="submit">SEND</button> </form> </body> </html>
💡 这里补充两个容易漏的点:
- 一定要把
g-recaptcha组件放在<form>标签内部,否则表单提交时不会携带验证响应值 - 加入了表单回显逻辑:如果验证失败跳转回来,用户之前输入的姓名、邮箱会保留,不用重新填(很多回答没提这个细节)
二、验证处理页面(verify.php)
这是核心的后端验证逻辑,负责把reCaptcha的响应发送给Google验证,判断用户是不是机器人。这里用curl来发送请求(比file_get_contents更稳定,很多服务器会禁用file_get_contents的远程请求):
<?php // 1. 先检查是否接收到reCaptcha的响应值,防止空提交 if(empty($_POST['g-recaptcha-response'])) { // 跳回表单页,提示错误,同时携带用户之前的输入 $name = urlencode($_POST['name'] ?? ''); $email = urlencode($_POST['email'] ?? ''); header("Location: form.html?error=empty_captcha&name=$name&email=$email"); exit; } // 2. 准备验证请求参数 $secret_key = "你的Secret Key"; // 替换成你自己的Secret Key $captcha_response = $_POST['g-recaptcha-response']; $user_ip = $_SERVER['REMOTE_ADDR']; // 3. 用curl发送请求到Google验证API $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://www.google.com/recaptcha/api/siteverify"); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query([ 'secret' => $secret_key, 'response' => $captcha_response, 'remoteip' => $user_ip ])); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $response = curl_exec($ch); curl_close($ch); // 4. 解析验证结果 $captcha_success = json_decode($response); // 5. 核心判断逻辑(和你提到的一致,补充了跳转处理) if ($captcha_success->success == false) { // 验证失败,跳回表单页提示机器人,携带用户输入 $name = urlencode($_POST['name'] ?? ''); $email = urlencode($_POST['email'] ?? ''); header("Location: form.html?error=bot&name=$name&email=$email"); exit; } else if ($captcha_success->success == true) { // 验证成功,这里可以先处理表单数据(比如存数据库),再跳转到成功页 $name = htmlspecialchars($_POST['name']); $email = htmlspecialchars($_POST['email']); // 示例:保存到数据库(根据你的需求修改) // $conn = new mysqli('localhost', 'username', 'password', 'dbname'); // $stmt = $conn->prepare("INSERT INTO submissions (name, email) VALUES (?, ?)"); // $stmt->bind_param("ss", $name, $email); // $stmt->execute(); // 跳转到成功页面 header("Location: success.php?name=$name"); exit; } else { // 其他异常情况,比如Google验证请求失败 header("Location: form.html?error=unknown"); exit; } ?>
💡 补充几个关键细节(很多回答没覆盖):
- 加入了空验证值检查:如果用户没点reCaptcha就提交,直接拦截
- 用
curl替代file_get_contents:避免服务器禁用远程请求导致验证失败 - 异常处理:当Google验证请求失败时,给用户友好的错误提示,而不是空白页面
- 跳转时携带用户输入:提升用户体验,不用重新填写表单
三、成功页面(success.php)
验证通过后跳转的页面,用来反馈提交成功的信息,或者处理后续业务:
<!DOCTYPE html> <html> <head> <title>提交成功</title> </head> <body> <h1>提交成功!</h1> <?php if(isset($_GET['name'])): ?> <p>感谢你,<?php echo htmlspecialchars($_GET['name']); ?>!我们会尽快联系你。</p> <?php endif; ?> <p><a href="form.html">返回表单</a></p> </body> </html>
最后几个必做的配置(很多人会忘)
- 在Google reCaptcha后台设置域名白名单:只有你指定的域名能使用你的site key,防止别人滥用
- 检查服务器环境:确保PHP开启了curl扩展(可以用
phpinfo()查看) - 永远不要依赖前端验证:前端的reCaptcha验证可以被绕过,必须通过verify.php的后端验证才算数
内容的提问来源于stack exchange,提问作者James_Duh
相关产品推荐
相关产品推荐

