MDL-53368 core_auth: Implement reCaptcha on login page
This commit is contained in:
@@ -79,6 +79,9 @@ define('AUTH_LOGIN_LOCKOUT', 4);
|
||||
/** Can not login becauser user is not authorised. */
|
||||
define('AUTH_LOGIN_UNAUTHORISED', 5);
|
||||
|
||||
/** Can not login, failed reCaptcha challenge. */
|
||||
define('AUTH_LOGIN_FAILED_RECAPTCHA', 6);
|
||||
|
||||
/**
|
||||
* Abstract authentication plugin.
|
||||
*
|
||||
@@ -1037,6 +1040,40 @@ function signup_captcha_enabled() {
|
||||
return !empty($CFG->recaptchapublickey) && !empty($CFG->recaptchaprivatekey) && $authplugin->is_captcha_enabled();
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns whether the captcha element is enabled for the login form, and the admin settings fulfil its requirements.
|
||||
* @return bool
|
||||
*/
|
||||
function login_captcha_enabled(): bool {
|
||||
global $CFG;
|
||||
return !empty($CFG->recaptchapublickey) && !empty($CFG->recaptchaprivatekey) && $CFG->enableloginrecaptcha == true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Check the submitted captcha is valid or not.
|
||||
*
|
||||
* @param string|bool $captcha The value submitted in the login form that we are validating.
|
||||
* If false is passed for the captcha, this function will always return true.
|
||||
* @return boolean If the submitted captcha is valid.
|
||||
*/
|
||||
function validate_login_captcha(string|bool $captcha): bool {
|
||||
global $CFG;
|
||||
if (!empty($CFG->alternateloginurl)) {
|
||||
// An external login page cannot use the reCaptcha.
|
||||
return true;
|
||||
}
|
||||
if ($captcha === false) {
|
||||
// The authenticate_user_login() is a core function was extended to validate captcha.
|
||||
// For existing uses other than the login form it does not need to validate the captcha.
|
||||
// Example: login/change_password_form.php or login/token.php.
|
||||
return true;
|
||||
}
|
||||
|
||||
require_once($CFG->libdir . '/recaptchalib_v2.php');
|
||||
$response = recaptcha_check_response(RECAPTCHA_VERIFY_URL, $CFG->recaptchaprivatekey, getremoteaddr(), $captcha);
|
||||
return $response['isvalid'];
|
||||
}
|
||||
|
||||
/**
|
||||
* Validates the standard sign-up data (except recaptcha that is validated by the form element).
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user