You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在含reCaptcha的三页面架构中实现PHP页面间跳转?含未公开步骤

完整实现reCaptcha v2验证(HTML + 双PHP页面方案)

刚折腾完一套带reCaptcha的表单验证流程,把所有细节(包括很多回答没提到的踩坑点)整理出来,正好对应你说的1个HTML页+2个PHP页的场景,直接抄改就能用!

一、HTML表单页面(比如命名为form.html)

这是用户填写信息并触发reCaptcha的页面,核心是要正确引入Google的reCaptcha脚本,并且把验证组件放到表单里:

<!DOCTYPE html>
<html>
<head>
    <title>带reCaptcha的表单</title>
    <!-- 引入reCaptcha v2脚本,替换成你自己的site key -->
    <script src="https://www.google.com/recaptcha/api.js" async defer></script>
</head>
<body>
    <!-- 如果有验证失败的错误提示,这里通过GET参数显示 -->
    <?php if(isset($_GET['error']) && $_GET['error'] == 'bot'): ?>
        <p style="color:red;">你是机器人!请重试!</p>
    <?php endif; ?>
    
    <form action="verify.php" method="POST">
        <label for="name">姓名:</label>
        <input type="text" id="name" name="name" value="<?php echo isset($_GET['name']) ? htmlspecialchars($_GET['name']) : ''; ?>" required><br>
        
        <label for="email">邮箱:</label>
        <input type="email" id="email" name="email" value="<?php echo isset($_GET['email']) ? htmlspecialchars($_GET['email']) : ''; ?>" required><br>
        
        <!-- reCaptcha验证组件,替换成你的site key -->
        <div class="g-recaptcha" data-sitekey="你的Site Key"></div><br>
        
        <button type="submit">SEND</button>
    </form>
</body>
</html>

💡 这里补充两个容易漏的点:

  • 一定要把g-recaptcha组件放在<form>标签内部,否则表单提交时不会携带验证响应值
  • 加入了表单回显逻辑:如果验证失败跳转回来,用户之前输入的姓名、邮箱会保留,不用重新填(很多回答没提这个细节)

二、验证处理页面(verify.php)

这是核心的后端验证逻辑,负责把reCaptcha的响应发送给Google验证,判断用户是不是机器人。这里用curl来发送请求(比file_get_contents更稳定,很多服务器会禁用file_get_contents的远程请求):

<?php
// 1. 先检查是否接收到reCaptcha的响应值,防止空提交
if(empty($_POST['g-recaptcha-response'])) {
    // 跳回表单页,提示错误,同时携带用户之前的输入
    $name = urlencode($_POST['name'] ?? '');
    $email = urlencode($_POST['email'] ?? '');
    header("Location: form.html?error=empty_captcha&name=$name&email=$email");
    exit;
}

// 2. 准备验证请求参数
$secret_key = "你的Secret Key"; // 替换成你自己的Secret Key
$captcha_response = $_POST['g-recaptcha-response'];
$user_ip = $_SERVER['REMOTE_ADDR'];

// 3. 用curl发送请求到Google验证API
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://www.google.com/recaptcha/api/siteverify");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query([
    'secret' => $secret_key,
    'response' => $captcha_response,
    'remoteip' => $user_ip
]));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);

// 4. 解析验证结果
$captcha_success = json_decode($response);

// 5. 核心判断逻辑(和你提到的一致,补充了跳转处理)
if ($captcha_success->success == false) {
    // 验证失败,跳回表单页提示机器人,携带用户输入
    $name = urlencode($_POST['name'] ?? '');
    $email = urlencode($_POST['email'] ?? '');
    header("Location: form.html?error=bot&name=$name&email=$email");
    exit;
} else if ($captcha_success->success == true) {
    // 验证成功,这里可以先处理表单数据(比如存数据库),再跳转到成功页
    $name = htmlspecialchars($_POST['name']);
    $email = htmlspecialchars($_POST['email']);
    
    // 示例:保存到数据库(根据你的需求修改)
    // $conn = new mysqli('localhost', 'username', 'password', 'dbname');
    // $stmt = $conn->prepare("INSERT INTO submissions (name, email) VALUES (?, ?)");
    // $stmt->bind_param("ss", $name, $email);
    // $stmt->execute();
    
    // 跳转到成功页面
    header("Location: success.php?name=$name");
    exit;
} else {
    // 其他异常情况,比如Google验证请求失败
    header("Location: form.html?error=unknown");
    exit;
}
?>

💡 补充几个关键细节(很多回答没覆盖):

  • 加入了空验证值检查:如果用户没点reCaptcha就提交,直接拦截
  • 用curl替代file_get_contents:避免服务器禁用远程请求导致验证失败
  • 异常处理:当Google验证请求失败时,给用户友好的错误提示,而不是空白页面
  • 跳转时携带用户输入:提升用户体验,不用重新填写表单

三、成功页面(success.php)

验证通过后跳转的页面,用来反馈提交成功的信息,或者处理后续业务:

<!DOCTYPE html>
<html>
<head>
    <title>提交成功</title>
</head>
<body>
    <h1>提交成功!</h1>
    <?php if(isset($_GET['name'])): ?>
        <p>感谢你,<?php echo htmlspecialchars($_GET['name']); ?>!我们会尽快联系你。</p>
    <?php endif; ?>
    <p><a href="form.html">返回表单</a></p>
</body>
</html>

最后几个必做的配置(很多人会忘)

  • 在Google reCaptcha后台设置域名白名单:只有你指定的域名能使用你的site key,防止别人滥用
  • 检查服务器环境:确保PHP开启了curl扩展(可以用phpinfo()查看)
  • 永远不要依赖前端验证:前端的reCaptcha验证可以被绕过,必须通过verify.php的后端验证才算数

内容的提问来源于stack exchange,提问作者James_Duh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:55:57