Cover image for project: NEXUS Google reCAPTCHA IN PROGRESS

Technical summary

NEXUS Google reCAPTCHA protects the NEXUS login against bots and automated attacks using Google reCAPTCHA (v2/v3): the widget is rendered in the form with the submit button locked until verification, and the token is validated server-side through the official siteverify endpoint with the remote IP. The secret key stays server-side only, with configuration through a panel modal.

Executed scope

  • Plugin registration (registerModal('recaptcha-modals', modals.php) + style: design.css in plugin.json) and backend functions in backend.php (110 lines): recaptcha_get_config(), recaptcha_save_config(), recaptcha_verify_token(), recaptcha_is_enabled() and recaptcha_get_site_key().
  • before_login filter (priority 5): when enabled, requires g-recaptcha-response in the POST; validates via recaptcha_verify_token($token, $_SERVER['REMOTE_ADDR']) and blocks login with a clear message on failure.
  • login_form_after_fields filter: injects the container with the .g-recaptcha widget (data-sitekey, onRecaptchaSuccess/onRecaptchaExpired callbacks), a hidden g-recaptcha-response input and loads api.js + assets/recaptcha.js.
  • Frontend (assets/recaptcha.js): locks the submit button (disabled + opacity) until the widget is solved; onRecaptchaSuccess fills the token and unlocks the button; onRecaptchaExpired locks it again.
  • Server-side verification: POST https://www.google.com/recaptcha/api/siteverify with secret, response and remoteip (when available), 10s timeout; JSON response with success and translated error-codes in the message.
  • Config protection: the secret key is never returned in full by the API — recaptcha_get_config returns secret_key_masked (first 6 + last 4 chars); key fields in the modal are password inputs.
  • 4 API actions: recaptcha_save_config (site_key + secret_key + enabled, both required to activate), recaptcha_get_config (with masked key), recaptcha_verify (manual token validation) and recaptcha_sitekey (public state site_key/enabled).
  • Fast Responses: fastr.json manifest with /recaptcha (no required arg), recaptcha_sitekey action — shows the plugin's public state.
  • On-demand only: cronjob.json with jobs: [] (no periodic routine needed); no CLI.
  • UI: Alpine.js config modal (recaptchaConfigModal(), 175 lines in modals.php) with a Configured/Not-configured badge, a link to the Google reCAPTCHA Admin Console and Site Key/Secret Key fields.
  • Lab environment: recaptcha_is_enabled() returns false on lab hosts (nx_is_lab_host()) — avoids locking the login in test environments.

Stack and tools

  • PHP 8 backend (no framework)
  • Google reCAPTCHA API v2/v3 — widget (api.js) + server-side siteverify
  • Alpine.js + Tailwind CSS (modal) + assets/recaptcha.js
  • Internal Plugin API (PluginManager filters/modals/actions + fastr.json)

Operational tags

  • Google
  • reCAPTCHA
  • Anti-bot
  • Login
  • Security
  • Siteverify
  • Web Protection
  • NEXUS Plugin

Operational result

  • Bot blocking at login: forces challenge completion before unlocking submit and validates the token on the server.
  • Server-side validation: siteverify with the secret key and remote IP — the frontend never decides alone.
  • Protected keys: the secret key never leaves the server; the API returns only a masked version.
  • Activation control: requires Site Key + Secret Key to enable; automatically disabled on lab hosts.
  • No routines: purely on-demand plugin — no cron or CLI.
  • Guided setup: modal with a direct link to the Google reCAPTCHA Admin Console.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Protects the NEXUS login against bots and automated attacks using Google reCAPTCHA (v2/v3): the widget is rendered in the form with the submit button locked until verification, and the token is validated server-side via the official siteverify endpoint with the remote IP and a server-only secret key; configuration through a panel modal.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.