Angular应用中reCAPTCHA v3的使用及验证策略咨询
Hey there! Let's tackle your reCAPTCHA v3 questions for your Angular app—they're great ones, since v3's approach is a bit different from the old checkbox-style v2.
First, it’s key to remember that reCAPTCHA v3 is built around actions: each token you get from grecaptcha.execute is tied to a specific user interaction (like submitting a form, loading sensitive data, or even a routine background refresh). The score Google returns isn’t a permanent "user trust badge"—it’s a rating of how likely that specific action is being performed by a human.
Here’s how to approach it:
- For high-risk actions (like form submissions, payment requests, or any action that could be abused by bots), you must generate a unique token for each action and send it along with the corresponding HTTP request. Your backend should validate this token directly with Google every time—this ensures you’re verifying the legitimacy of that exact interaction, not just the initial app load.
- For low-risk, frequent background requests (like auto-refreshing non-sensitive data), you don’t need to send a token every single time. But if these requests could be targeted by scrapers, you can generate a token on user-initiated interactions (e.g., when they click a button, scroll, or type) and reuse it for a short window (since tokens expire after 2 minutes) instead of relying on an app-startup token.
Critical note: Never store the score in Angular (or any client-side storage). Client-side data can easily be tampered with by attackers—only the backend’s direct validation with Google gives you a trusted score. Storing it client-side completely defeats the purpose of reCAPTCHA.
Absolutely—reCAPTCHA v3’s score is context-dependent, so refreshing the token at the right times ensures you’re getting the most accurate assessment. Here are the key scenarios to re-generate tokens:
- After user inactivity: If a user leaves the tab idle for 5+ minutes, their old token’s score won’t reflect their current interaction (they might come back and start performing actions again). Trigger
grecaptcha.executewhen they resume activity (e.g., mouse movement, keyboard input) to get a fresh score. - Right before high-risk actions: Even if the user is active, always generate a new token immediately before a critical action (like clicking a form submit button). This ties the score directly to the context of that specific action, which is far more reliable than reusing an old token.
- During long-lived sessions: If users stay on your app for hours, generate a new token every 15-30 minutes while they’re active. This keeps the trust assessment up-to-date as their interaction patterns change.
Also, keep in mind that reCAPTCHA v3 tokens expire after 2 minutes, so you can’t reuse them indefinitely anyway—generating new tokens when needed ensures you’re working with valid, context-aware data.
内容的提问来源于stack exchange,提问作者Jack

