IN PROGRESS
Technical summary
Additional NEXUS plugin that protects login against bots with Cloudflare Turnstile without intrusive user challenges. PluginManager hooks inject the widget and validate its token server-side through the siteverify API; lab environments receive an automatic bypass so development and tests remain accessible.
Executed scope
- Login form integration through two
PluginManagerfilters: - Explicit widget rendering with a light theme; the submit button stays disabled until the token is obtained (blocks requests without a challenge).
- Server-side verification
turnstile_verify_token():curlPOST tohttps://challenges.cloudflare.com/turnstile/v0/siteverifywithsecret,responseandremoteip(10s timeout), witherror-codesand non-200 HTTP handling. - Automatic bypass on lab hosts via
nx_is_lab_host()— Turnstile never blocks development environments. - Settings persisted in
admin_configs(plugin.cloudflare-turnstilekey):site_key,secret_key,enabledandprotected_pages(default['login']), with partial merge on save and required-key validation when enabling. - In-panel configuration modal (Alpine.js): Configured/Not configured badge, site key preview, site/secret key fields and the official "How to get the keys" link.
- 4 registered API actions:
turnstile_save_config,turnstile_get_config(exposessecret_key_maskedinfirst8...last4format),turnstile_verifyandturnstile_sitekey. - Lean architecture:
plugin.php(hooks + actions),backend.php(110 lines),modals.php(modal UI) andassets/turnstile.js(client-side widget rendering) — no dedicated tables.
- before_login (priority 5): requires the cf-turnstile-response token and invalidates the login if verification fails. - login_form_after_fields: injects a styled container (#turnstile-container), the #turnstile-widget with data-sitekey, the hidden input cf-turnstile-response and the Turnstile scripts (api.js with render=explicit and the global onloadTurnstileCallback).
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (settings in
admin_configs; no dedicated tables) - Alpine.js + Tailwind CSS
- cURL (Cloudflare
siteverifyverification) - Cloudflare Turnstile (client-side widget + server-side verification API)
- NEXUS plugin system (
PluginManager— filters and modals)
Operational tags
- Cloudflare
- Turnstile
- CAPTCHA
- Security
Operational outcome
- Hardened NEXUS login against bots and automated brute-force attacks without degrading user experience (Turnstile's invisible/managed challenge).
- 100% hook-based plugin integration — the NEXUS core needed no changes and the protection can be toggled from the panel.
- Automatic lab-host bypass ensures development and tests are never blocked by the CAPTCHA.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that adds bot protection to login with Cloudflare Turnstile — a non-intrusive challenge, server-side verification via siteverify and automatic bypass on lab hosts.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- cURL
- Cloudflare Turnstile
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.