ReCaptcha与formhandler.php集成失败问题排查求助
Troubleshooting Your reCAPTCHA Integration with formhandler.php
Hey there, let’s work through why your reCAPTCHA is still sending users to error.php even when they check the box. This is a super common issue, so we’ll go through the most likely fixes step by step.
First, Rule Out Basic Configuration Mistakes
- Double-check your API keys: It’s easy to mix up the site key (used in your frontend HTML) and secret key (used in
formhandler.php). Make sure both are copied correctly from your Google reCAPTCHA dashboard, and that your domain is whitelisted in the dashboard. - Verify the frontend field name: Ensure your HTML form includes the reCAPTCHA widget with the correct name attribute—Google’s widget uses
g-recaptcha-response, so your form should be sending that field via POST.
Fix the Validation Logic Order & Structure
The most common culprit here is either misplaced validation code or incorrect logic in your formhandler.php. Let’s outline the correct flow for your handler:
- First, check if the reCAPTCHA response exists: If the user didn’t check the box,
$_POST['g-recaptcha-response']won’t be set—so we handle that first. - Send the verification request to Google: Make sure this request is properly formatted.
- Check the verification result: Only proceed with form processing if the response is successful.
Here’s a corrected snippet for your formhandler.php:
// 1. Check if reCAPTCHA response is present if (!isset($_POST['g-recaptcha-response']) || empty($_POST['g-recaptcha-response'])) { header("Location: error.php"); exit(); } // 2. Verify with Google reCAPTCHA API $secretKey = "YOUR_RECAPTCHA_SECRET_KEY"; $recaptchaResponse = $_POST['g-recaptcha-response']; $userIp = $_SERVER['REMOTE_ADDR']; // Build the verification request $verifyUrl = "https://www.google.com/recaptcha/api/siteverify"; $postData = http_build_query([ 'secret' => $secretKey, 'response' => $recaptchaResponse, 'remoteip' => $userIp ]); // Send request (use file_get_contents or curl) $context = stream_context_create([ 'http' => [ 'method' => 'POST', 'header' => 'Content-Type: application/x-www-form-urlencoded', 'content' => $postData ] ]); $verifyResult = file_get_contents($verifyUrl, false, $context); $responseData = json_decode($verifyResult); // 3. Check if verification succeeded if (!$responseData->success) { // Even if the box was checked, verification failed (e.g., bot detected) header("Location: error.php"); exit(); } // --- If we get here, reCAPTCHA is valid! --- // Proceed with your form processing logic (validate fields, send emails, etc.) // After processing, redirect to success page header("Location: success.php"); exit();
Additional Checks to Fix Edge Cases
- Avoid output before header redirects: Make sure there’s no whitespace, echo statements, or HTML output before your
header()calls. Any output will break the redirect, which might make it look like the verification failed when it didn’t. - Check if file_get_contents is enabled: Some servers disable
file_get_contentsfor HTTP requests. If that’s the case, replace the request with a curl alternative:$ch = curl_init($verifyUrl); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $postData); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $verifyResult = curl_exec($ch); curl_close($ch); - Check Google’s reCAPTCHA logs: Head to your Google reCAPTCHA dashboard to see if there are any error messages (like invalid keys or domain mismatches) that can point you to the issue.
Give these steps a try—9 times out of 10, it’s either a key mix-up, misplaced validation logic, or a broken redirect due to accidental output.
内容的提问来源于stack exchange,提问作者shimda
相关产品推荐
相关产品推荐

