Skip to content

feat: add Tier 1/2 security, transport timeout, and DX enhancements - #636

Merged
rowan-m merged 2 commits into
mainfrom
feat/tier1-and-tier2-improvements
Sep 23, 2026
Merged

rowan-m merged 2 commits into
mainfrom
feat/tier1-and-tier2-improvements

Conversation

@rowan-m

@rowan-m rowan-m commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Overview

Implements backwards-compatible security hardening, transport configurability, and developer experience (DX) enhancements across src/, examples/, tests/, composer.json, and AGENTS.md.


What's Changed

1. Core Security & Type Hardening (src/)

  • Sensitive Parameter Redaction: Added #[\SensitiveParameter] to $secret in ReCaptcha::__construct() and RequestParameters::__construct() to prevent secret key exposure in PHP stack traces and error logs.
  • Safe Error Code Filtering: Updated Response::fromJson() to filter error-codes arrays using array_values(array_filter(..., 'is_string')) rather than relying on PHPDoc type overrides.

2. Additive Developer Experience & Transport Configurability (src/)

  • Configurable Transport Timeouts: Added an optional int $timeout = 60 constructor parameter to CurlPost, Post, and SocketPost so callers can customize request latency budgets while preserving the 60-second default.
  • Explicit Connect Timeout in CurlPost: Set CURLOPT_CONNECTTIMEOUT => $this->timeout alongside CURLOPT_TIMEOUT => $this->timeout in CurlPost::submit().
  • Header/Body Split Limit in SocketPost: Added $limit = 2 to preg_split() in SocketPost::submit().
  • JsonSerializable Support: Implemented \JsonSerializable (jsonSerialize(): array) on Response.
  • Alternative Global Endpoint Constant: Added ReCaptcha::SITE_VERIFY_URL_ALTERNATIVE (https://www.recaptcha.net/recaptcha/api/siteverify).

3. Example Security & Cleanup (examples/)

  • Server-Side Action Allowlist: Updated examples/recaptcha-v3-verify.php to validate $_GET / $_SERVER superglobals and verify $action against an explicit server-side allowlist rather than trusting arbitrary client-provided $_GET['action'] values.
  • DOM XSS Hardening: Replaced .innerHTML with .textContent and added encodeURIComponent(token) in examples/recaptcha-v3-request-scores.php and examples/recaptcha-content-security-policy.php.
  • Sunset Analytics Removal: Removed deprecated Universal Analytics (UA-123057962-1) tags from examples/recaptcha-request-*.php.

4. Packaging, Documentation & Unit Tests (composer.json, AGENTS.md, tests/)

  • Added suggest (ext-curl, ext-openssl) to composer.json.
  • Aligned AGENTS.md release checklist (public const VERSION and composer audit).
  • Fixed ISO-8601 date format ('Y-m-d\TH:i:s\Z') in ReCaptchaTest and added unit tests maintaining 100% class, method, and line coverage (75 tests, 214 assertions) and passing roave/backward-compatibility-check.

@coveralls

coveralls commented Sep 22, 2026 •

Copy link
Copy Markdown

Coverage Status

coverage: 100.0%. remained the same — feat/tier1-and-tier2-improvements into main

@rowan-m
rowan-m merged commit 50a03db into main Sep 23, 2026
13 checks passed
@rowan-m
rowan-m deleted the feat/tier1-and-tier2-improvements branch September 23, 2026 13:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants