{"_id":"@activescott/auth-botcheck-turnstile","name":"@activescott/auth-botcheck-turnstile","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@activescott/auth-botcheck-turnstile","version":"0.1.0","description":"Cloudflare Turnstile bot check for @activescott/auth","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc","dev":"tsc --watch","typecheck":"tsc --noEmit","test":"vitest run","prepublishOnly":"npm run build"},"keywords":["auth","authentication","turnstile","cloudflare","captcha","bot","abuse"],"author":{"name":"Scott Willeke"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/activescott/auth.git","directory":"packages/auth-botcheck-turnstile"},"peerDependencies":{"@activescott/auth":">=3.1.0"},"devDependencies":{"@activescott/auth":"*","@types/node":"^22","typescript":"^5.7.2","vitest":"^4.0.16"},"_id":"@activescott/auth-botcheck-turnstile@0.1.0","gitHead":"db7ce93a973cb8267c1958644f8faafa9aed72ec","bugs":{"url":"https://github.com/activescott/auth/issues"},"homepage":"https://github.com/activescott/auth#readme","_nodeVersion":"22.23.2","_npmVersion":"10.9.8","dist":{"integrity":"sha512-1UPZ/8K/P9i6nWnEmYIQp5At1yALI26BDcLxJort1y0BfrXU627CkY6gI17qhBqxKDbFTnsRRr8u5YUaztJkXA==","shasum":"52d1659140910e0a6f03d8d46124102a8ca5460e","tarball":"https://registry.npmjs.org/@activescott/auth-botcheck-turnstile/-/auth-botcheck-turnstile-0.1.0.tgz","fileCount":11,"unpackedSize":14155,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEHyYeVo7pJveZSNZbz8phzcxE6XqR+uGgLFjrpAfrdlAiBa+L38p+vt4SsXMATSb/pEomvAYW1pUtEn0HgHswLdsQ=="}]},"_npmUser":{"name":"activescott","email":"scott@willeke.com"},"directories":{},"maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth-botcheck-turnstile_0.1.0_1786062399196_0.9820797905325518"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-07T00:26:38.870Z","0.1.0":"2026-08-07T00:26:39.356Z","modified":"2026-08-07T00:26:39.586Z"},"maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"description":"Cloudflare Turnstile bot check for @activescott/auth","homepage":"https://github.com/activescott/auth#readme","keywords":["auth","authentication","turnstile","cloudflare","captcha","bot","abuse"],"repository":{"type":"git","url":"git+https://github.com/activescott/auth.git","directory":"packages/auth-botcheck-turnstile"},"author":{"name":"Scott Willeke"},"bugs":{"url":"https://github.com/activescott/auth/issues"},"license":"MIT","readme":"# @activescott/auth-botcheck-turnstile\n\n[Cloudflare Turnstile](https://developers.cloudflare.com/turnstile/) bot check\nfor [`@activescott/auth`](https://www.npmjs.com/package/@activescott/auth).\n\n`@activescott/auth` protects the initiate endpoints out of the box with per-IP\nand per-recipient rate limits and a minimum form-fill time —\nnone of which need a third party. Add this package when you want a hosted bot\ncheck on top of those layers. It is a separate package so applications that do\nnot use Turnstile never install it.\n\nZero runtime dependencies: verification is one `fetch` to Cloudflare's\n`siteverify` endpoint.\n\n## Install\n\n```bash\nnpm install @activescott/auth-botcheck-turnstile\n```\n\n## Server\n\n```typescript\nimport { Auth } from \"@activescott/auth\"\nimport { TurnstileBotCheck } from \"@activescott/auth-botcheck-turnstile\"\n\nconst auth = new Auth({\n  // ...session, stores, providers\n  abuse: {\n    botChecks: [\n      new TurnstileBotCheck({ secretKey: process.env.TURNSTILE_SECRET_KEY }),\n    ],\n  },\n})\n```\n\nA request that fails the check is answered exactly as a successful send would\nbe, and the rejection is logged with the reason Cloudflare returned.\n\n## Client\n\nRender the widget inside the login form so the browser posts the\n`cf-turnstile-response` field along with the address:\n\n```html\n<script\n  src=\"https://challenges.cloudflare.com/turnstile/v0/api.js\"\n  async\n  defer\n></script>\n\n<form method=\"post\" action=\"/auth/email/initiate\">\n  <input type=\"email\" name=\"email\" required />\n  <div class=\"cf-turnstile\" data-sitekey=\"YOUR_SITE_KEY\"></div>\n  <button type=\"submit\">Send magic link</button>\n</form>\n```\n\n## Configuration\n\n| Option      | Default                   | Notes                                                            |\n| ----------- | ------------------------- | ---------------------------------------------------------------- |\n| `secretKey` | required                  | Turnstile **secret** key, never the site key                     |\n| `fieldName` | `\"cf-turnstile-response\"` | Form field carrying the widget token                             |\n| `verifyUrl` | Cloudflare `siteverify`   | Override for tests or a proxy                                    |\n| `timeoutMs` | `5000`                    | How long to wait for `siteverify`                                |\n| `failOpen`  | `true`                    | Allow the request when Cloudflare is unreachable; logs a warning |\n\n`failOpen` defaults to `true` because the rate limits still apply\nwhen Turnstile cannot be reached, and an outage at Cloudflare should not lock\nevery user out of signing in. Set it to `false` to fail closed instead.\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-8de6f76dba3323ab8b1ae3bf4d36092c"}