You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ReCaptcha与formhandler.php集成失败问题排查求助

Troubleshooting Your reCAPTCHA Integration with formhandler.php

Hey there, let’s work through why your reCAPTCHA is still sending users to error.php even when they check the box. This is a super common issue, so we’ll go through the most likely fixes step by step.

First, Rule Out Basic Configuration Mistakes

  • Double-check your API keys: It’s easy to mix up the site key (used in your frontend HTML) and secret key (used in formhandler.php). Make sure both are copied correctly from your Google reCAPTCHA dashboard, and that your domain is whitelisted in the dashboard.
  • Verify the frontend field name: Ensure your HTML form includes the reCAPTCHA widget with the correct name attribute—Google’s widget uses g-recaptcha-response, so your form should be sending that field via POST.

Fix the Validation Logic Order & Structure

The most common culprit here is either misplaced validation code or incorrect logic in your formhandler.php. Let’s outline the correct flow for your handler:

  1. First, check if the reCAPTCHA response exists: If the user didn’t check the box, $_POST['g-recaptcha-response'] won’t be set—so we handle that first.
  2. Send the verification request to Google: Make sure this request is properly formatted.
  3. Check the verification result: Only proceed with form processing if the response is successful.

Here’s a corrected snippet for your formhandler.php:

// 1. Check if reCAPTCHA response is present
if (!isset($_POST['g-recaptcha-response']) || empty($_POST['g-recaptcha-response'])) {
    header("Location: error.php");
    exit();
}

// 2. Verify with Google reCAPTCHA API
$secretKey = "YOUR_RECAPTCHA_SECRET_KEY";
$recaptchaResponse = $_POST['g-recaptcha-response'];
$userIp = $_SERVER['REMOTE_ADDR'];

// Build the verification request
$verifyUrl = "https://www.google.com/recaptcha/api/siteverify";
$postData = http_build_query([
    'secret' => $secretKey,
    'response' => $recaptchaResponse,
    'remoteip' => $userIp
]);

// Send request (use file_get_contents or curl)
$context = stream_context_create([
    'http' => [
        'method' => 'POST',
        'header' => 'Content-Type: application/x-www-form-urlencoded',
        'content' => $postData
    ]
]);
$verifyResult = file_get_contents($verifyUrl, false, $context);
$responseData = json_decode($verifyResult);

// 3. Check if verification succeeded
if (!$responseData->success) {
    // Even if the box was checked, verification failed (e.g., bot detected)
    header("Location: error.php");
    exit();
}

// --- If we get here, reCAPTCHA is valid! ---
// Proceed with your form processing logic (validate fields, send emails, etc.)

// After processing, redirect to success page
header("Location: success.php");
exit();

Additional Checks to Fix Edge Cases

  • Avoid output before header redirects: Make sure there’s no whitespace, echo statements, or HTML output before your header() calls. Any output will break the redirect, which might make it look like the verification failed when it didn’t.
  • Check if file_get_contents is enabled: Some servers disable file_get_contents for HTTP requests. If that’s the case, replace the request with a curl alternative:
    $ch = curl_init($verifyUrl);
    curl_setopt($ch, CURLOPT_POST, true);
    curl_setopt($ch, CURLOPT_POSTFIELDS, $postData);
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
    $verifyResult = curl_exec($ch);
    curl_close($ch);
    
  • Check Google’s reCAPTCHA logs: Head to your Google reCAPTCHA dashboard to see if there are any error messages (like invalid keys or domain mismatches) that can point you to the issue.

Give these steps a try—9 times out of 10, it’s either a key mix-up, misplaced validation logic, or a broken redirect due to accidental output.

内容的提问来源于stack exchange,提问作者shimda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:41:07