reCAPTCHA

reCAPTCHA

Google reCAPTCHA v2 & v3 fields & validation

v3

Field

The token is fetched on form submit (not on page load), preventing unexpected challenge popups. The form is auto-resolved via closest("form") — no formId needed when the hidden input is inside the form.

use Yiisoft\FormModel\FormModel;
use YiiRocks\Recaptcha\RecaptchaV3Field;
use YiiRocks\Recaptcha\RecaptchaV3Badge;

echo RecaptchaV3Field::field($form, 'captcha')
    ->withAction('login')
    ->withFormId('login-form')
    ->withBadge(RecaptchaV3Badge::Hidden)
    ->render();

Options

withSiteKey(string)
Explicit site key override. Optional — pulled from config by default. Default: from config.
withAction(string)
Action name sent to Google (must match the rule's action if set). Default: ''.
withFormId(string)
Explicit form ID. When omitted the form is auto-resolved via closest("form").
withBadge(RecaptchaV3Badge)
BottomRight, BottomLeft, or Hidden. Default: BottomRight.
withJsApiUrl(string)
Custom JS API URL. Default: Google CDN.
withTranslator(?TranslatorInterface)
Translator for the hidden badge legal notice. Default: from registry.
withExecuteTimeout(?int)
Fallback form submission timeout (null = disabled). Default: 5000 ms.

Inherited from InputField

->name(string)
Override the hidden input name. Default: auto-derived from form model as FormName[attribute].
->inputId(?string)
Override the hidden input ID. Default: auto-generated unique ID.

Container (inherited from BaseField)

->containerTag(string)
Wrapper tag. Default: 'div'.
->containerClass(string ...)
Wrapper CSS class(es). Default: 'mb-3'.
->useContainer(bool)
Enable/disable wrapper. Default: true.
->containerAttributes(array)
Set all wrapper attributes.
->addContainerAttributes(array)
Merge additional wrapper attributes.

Hidden badge: When Badge::Hidden is selected, the legal notice text ("This site is protected by reCAPTCHA…") is displayed automatically and translated when a translator is available (either via withTranslator() or through RecaptchaRegistry).

Validation

Use the attribute on your form model property:

use YiiRocks\Recaptcha\RecaptchaV3Rule;

final class LoginForm
{
    #[RecaptchaV3Rule(
        threshold: 0.5,
        action: 'login',
        sendRemoteIp: true,
    )]
    public string $gRecaptchaResponse = '';
}

Important: If you set ->withAction('...') on the v3 field, you must also set action: '...' on the rule with the same value. If neither is set, no action is sent and the check is skipped entirely.

Rule parameters

threshold
Minimum score (0.0 — 1.0). Default: 0.5.
action
Expected action name (skipped if null). Default: null.
message
Error message (translatable). Default: 'The CAPTCHA verification failed.'.
scoreTooLowMessage
Error when score is below threshold. Default: 'The CAPTCHA score is too low.'.
actionMismatchMessage
Error when action doesn't match. Default: 'The CAPTCHA action does not match.'.
secret
Custom secret (uses config default if null). Default: null.
sendRemoteIp
Whether to include the user's IP in verification. Default: false.