IN PROGRESS
Technical summary
NEXUS hCaptcha Protection protects the NEXUS login against bots using hCaptcha (Enterprise/Standard, privacy-focused): the widget is rendered in the form with the submit button locked until verification, and the token is validated server-side through the official siteverify endpoint with the remote IP. The secret key stays server-side only, with configuration through a panel modal, and the filter accepts hCaptcha or reCAPTCHA tokens for compatibility.
Executed scope
- Plugin registration (
registerModal('hcaptcha-modals', modals.php)+style: design.cssin plugin.json) and backend functions inbackend.php(110 lines):hcaptcha_get_config(),hcaptcha_save_config(),hcaptcha_verify_token(),hcaptcha_is_enabled()andhcaptcha_get_site_key(). before_loginfilter (priority 5): when enabled, requiresh-captcha-responsein the POST (also acceptsg-recaptcha-responsefor compatibility); validates viahcaptcha_verify_token($token, $_SERVER['REMOTE_ADDR'])and blocks login with a clear message on failure.login_form_after_fieldsfilter: injects the#hcaptcha-containerwith the.h-captchawidget (data-sitekey,onHcaptchaSuccess/onHcaptchaExpiredcallbacks) and loads the hCaptchaapi.js+assets/hcaptcha.js.- Frontend (
assets/hcaptcha.js, 27 lines): locks the submit button (disabled + opacity + cursor) until the widget is solved;onHcaptchaSuccessunlocks the button;onHcaptchaExpiredlocks it again. - Server-side verification:
POST https://api.hcaptcha.com/siteverifywithsecret,responseandremoteip(when available), 10s timeout; JSON response withsuccessand translatederror-codesin the message. - Config protection: the secret key is never returned in full by the API —
hcaptcha_get_configreturnssecret_key_masked(first 6 + last 4 chars); key fields in the modal arepasswordinputs. - 4 API actions:
hcaptcha_save_config(site_key + secret_key + enabled, both required to activate),hcaptcha_get_config(with masked key),hcaptcha_verify(manual token validation) andhcaptcha_sitekey(public state site_key/enabled). - Fast Responses:
fastr.jsonmanifest with/hcaptcha(no required arg),hcaptcha_sitekeyaction — shows the plugin's public state. - On-demand only:
cronjob.jsonwithjobs: [](no periodic routine needed); no CLI. - UI: Alpine.js config modal (
hcaptchaConfigModal(), 175 lines inmodals.php) with a Configured/Not-configured badge, a link to the hCaptcha dashboard (dashboard.hcaptcha.com) and Site Key/Secret Key fields. - Lab environment:
hcaptcha_is_enabled()returnsfalseon lab hosts (nx_is_lab_host()) — avoids locking the login in test environments.
Stack and tools
- PHP 8 backend (no framework)
- hCaptcha API — widget (
js.hcaptcha.com/1/api.js) + server-side siteverify - Alpine.js + Tailwind CSS (modal) +
assets/hcaptcha.js - Internal Plugin API (PluginManager filters/modals/actions +
fastr.json)
Operational tags
- hCaptcha
- Anti-bot
- Login
- Security
- Siteverify
- Privacy
- Web Protection
- NEXUS Plugin
Operational result
- Bot blocking at login: forces challenge completion before unlocking submit and validates the token on the server.
- Server-side validation: siteverify with the secret key and remote IP — the frontend never decides alone.
- Protected keys: the secret key never leaves the server; the API returns only a masked version.
- Privacy: hCaptcha is a privacy-focused alternative, with the modal highlighting the official dashboard.
- Activation control: requires Site Key + Secret Key to enable; automatically disabled on lab hosts.
- No routines: purely on-demand plugin — no cron or CLI.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Protects the NEXUS login against bots using hCaptcha (privacy-focused): the widget is rendered in the form with the submit button locked until verification, and the token is validated server-side via the official siteverify endpoint with the remote IP and a server-only secret key; configuration through a panel modal, and the filter accepts hCaptcha or reCAPTCHA tokens for compatibility.
Architecture and organization
- PHP 8
- hCaptcha API
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.