IN PROGRESS
Technical summary
NEXUS Google reCAPTCHA protects the NEXUS login against bots and automated attacks using Google reCAPTCHA (v2/v3): the widget is rendered in the form with the submit button locked until verification, and the token is validated server-side through the official siteverify endpoint with the remote IP. The secret key stays server-side only, with configuration through a panel modal.
Executed scope
- Plugin registration (
registerModal('recaptcha-modals', modals.php)+style: design.cssin plugin.json) and backend functions inbackend.php(110 lines):recaptcha_get_config(),recaptcha_save_config(),recaptcha_verify_token(),recaptcha_is_enabled()andrecaptcha_get_site_key(). before_loginfilter (priority 5): when enabled, requiresg-recaptcha-responsein the POST; validates viarecaptcha_verify_token($token, $_SERVER['REMOTE_ADDR'])and blocks login with a clear message on failure.login_form_after_fieldsfilter: injects the container with the.g-recaptchawidget (data-sitekey,onRecaptchaSuccess/onRecaptchaExpiredcallbacks), a hiddeng-recaptcha-responseinput and loadsapi.js+assets/recaptcha.js.- Frontend (
assets/recaptcha.js): locks the submit button (disabled + opacity) until the widget is solved;onRecaptchaSuccessfills the token and unlocks the button;onRecaptchaExpiredlocks it again. - Server-side verification:
POST https://www.google.com/recaptcha/api/siteverifywithsecret,responseandremoteip(when available), 10s timeout; JSON response withsuccessand translatederror-codesin the message. - Config protection: the secret key is never returned in full by the API —
recaptcha_get_configreturnssecret_key_masked(first 6 + last 4 chars); key fields in the modal arepasswordinputs. - 4 API actions:
recaptcha_save_config(site_key + secret_key + enabled, both required to activate),recaptcha_get_config(with masked key),recaptcha_verify(manual token validation) andrecaptcha_sitekey(public state site_key/enabled). - Fast Responses:
fastr.jsonmanifest with/recaptcha(no required arg),recaptcha_sitekeyaction — shows the plugin's public state. - On-demand only:
cronjob.jsonwithjobs: [](no periodic routine needed); no CLI. - UI: Alpine.js config modal (
recaptchaConfigModal(), 175 lines inmodals.php) with a Configured/Not-configured badge, a link to the Google reCAPTCHA Admin Console and Site Key/Secret Key fields. - Lab environment:
recaptcha_is_enabled()returnsfalseon lab hosts (nx_is_lab_host()) — avoids locking the login in test environments.
Stack and tools
- PHP 8 backend (no framework)
- Google reCAPTCHA API v2/v3 — widget (
api.js) + server-side siteverify - Alpine.js + Tailwind CSS (modal) +
assets/recaptcha.js - Internal Plugin API (PluginManager filters/modals/actions +
fastr.json)
Operational tags
- reCAPTCHA
- Anti-bot
- Login
- Security
- Siteverify
- Web Protection
- NEXUS Plugin
Operational result
- Bot blocking at login: forces challenge completion before unlocking submit and validates the token on the server.
- Server-side validation: siteverify with the secret key and remote IP — the frontend never decides alone.
- Protected keys: the secret key never leaves the server; the API returns only a masked version.
- Activation control: requires Site Key + Secret Key to enable; automatically disabled on lab hosts.
- No routines: purely on-demand plugin — no cron or CLI.
- Guided setup: modal with a direct link to the Google reCAPTCHA Admin Console.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Protects the NEXUS login against bots and automated attacks using Google reCAPTCHA (v2/v3): the widget is rendered in the form with the submit button locked until verification, and the token is validated server-side via the official siteverify endpoint with the remote IP and a server-only secret key; configuration through a panel modal.
Architecture and organization
- PHP 8
- Google reCAPTCHA API v2/v3
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.