registry = $registry; $this->DB = $this->registry->DB(); $this->settings =& $this->registry->fetchSettings(); $this->member = $this->registry->member(); /* Settings */ $this->public_key = trim( $this->settings['recaptcha_public_key'] ); $this->private_key = trim( $this->settings['recaptcha_private_key'] ); $this->useSSL = ( $this->settings['logins_over_https'] or $this->registry->output->isHTTPS ); } /** * Returns the reCAPTCHA template (javascript and non-javascript version). * This is called from the browser, and the resulting reCAPTCHA HTML widget * is embedded within the HTML form it was called from. * * @return @e string * * Example Usage: * @code * $recaptchaForm = $this->getTemplate(); * @endcode */ public function getTemplate() { if ( ! $this->public_key ) { return ''; } if ($this->useSSL) { $server = RECAPTCHA_API_SECURE_SERVER; } else { $server = RECAPTCHA_API_SERVER; } $html = ''; $html .= ""; $html .= ' '; //----------------------------------------- // Return Template Bit //----------------------------------------- return $this->registry->output->getTemplate('global_other')->captchaRecaptcha( $html ); } /** * Validates the entered captcha code, returning true on success and false on failure * * @return @e boolean * * Example Usage: * @code * $isValid = $this->validate(); * @endcode */ public function validate() { if ( !$this->private_key ) { $this->error = 'no_private_key'; return FALSE; } $captcha_unique_id = $_REQUEST['recaptcha_challenge_field']; $captcha_input = $_REQUEST['recaptcha_response_field']; //----------------------------------------- // Path disclosure prevention //----------------------------------------- if ( is_array( $captcha_input ) ) { return false; } if ( $captcha_input == null || strlen($captcha_input) == 0 || $captcha_unique_id == null || strlen($captcha_unique_id) == 0) { return false; } $classToLoad = IPSLib::loadLibrary( IPS_KERNEL_PATH . '/classFileManagement.php', 'classFileManagement' ); $communication = new $classToLoad(); $response = $communication->postFileContents( RECAPTCHA_VERIFY_SERVER . "/recaptcha/api/verify", array( 'privatekey' => $this->private_key, 'remoteip' => $this->member->ip_address, 'challenge' => $captcha_unique_id, 'response' => $captcha_input ) ); $answers = explode( "\n", $response ); if ( trim($answers[0]) == 'true' ) { return TRUE; } else { /** * It's an error */ $this->error = $answers[1]; return FALSE; } } }