Skip to content

fix: persist FusionCaptcha state when cache is disabled - #166

Merged
Nightprince merged 2 commits into
FusionWowCMS:mainfrom
Dutchevil:fix/fusion-captcha-cache-disabled
Sep 26, 2026
Merged

Nightprince merged 2 commits into
FusionWowCMS:mainfrom
Dutchevil:fix/fusion-captcha-cache-disabled

Conversation

@Dutchevil

Copy link
Copy Markdown
Contributor

Summary

  • Persist FusionCaptcha challenge/token state in a dedicated file-backed cache under writable/cache/data/captcha, independent of FusionCMS' global data cache toggle.
  • Prevent reusing an active user-agent-bound challenge when another browser behind the same IP requests a challenge, avoiding ua_mismatch on redemption.
  • Update captcha garbage collection to clean the dedicated captcha cache files.

Why

When $config['cache'] = false, FusionCaptcha still returns a challenge from /captcha/challenge, but the challenge is not saved through the global Cache library. /captcha/redeem then cannot find the challenge and returns {"success":false,"error":"expired"}, causing the login/register widget to fail after solving.

A live FusionCMS install reproduced this as a captcha widget that loaded to the final step and then displayed Error! Please try again.

Test plan

  • git diff --check
  • php -l application/libraries/FusionCaptcha.php using PHP CLI in Docker
  • Verified on a live FusionCMS install that /captcha/redeem changed from expired to success:true and the browser widget reaches Verified!.

Store FusionCaptcha challenge/token state in its own file-backed cache so captcha verification still works when FusionCMS global data cache is disabled.

Also avoid reusing a user-agent-bound challenge for another browser sharing the same IP, preventing ua_mismatch during redemption.
@Dutchevil
Dutchevil force-pushed the fix/fusion-captcha-cache-disabled branch from 39a9bf7 to a067ebb Compare September 24, 2026 11:32
Add the missing admin language string used by the captcha type selector so the settings page renders when FusionCaptcha is available.
@Nightprince
Nightprince merged commit fab7de8 into FusionWowCMS:main Sep 26, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants