fix(recaptcha): log verification responses and errors #4361
+27
−1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
All Submissions:
Changes proposed in this Pull Request:
Adds some debug and error logging when a site makes a verification request (assessment) to the reCAPTCHA API. This will let us better estimate reCAPTCHA usage across the Newspack platform.
This only logs when the request is sent server-side—it doesn't separately log requests sent directly to the reCAPTCHA API via JS when using v2. This is because we double-verify captcha tokens fetched via JS with a server-side request to avoid unverified direct POST requests. Since the server-side requests are simply verifying the captcha token that was fetched on the front-end (and not fetching a new token to assess the validity of the request), I don't believe this counts as a separate assessment—but it's unclear from Google's documentation exactly how they count assessments on their end.
Closes NPPD-900.
How to test the changes in this Pull Request:
newspack_logwith info about the request: reCAPTCHA version (v2_invisibleorv3), score (if using v3), timestamp of the challenge completion (if using v2), success status, hostname, etc.Other information: