{"_id":"@apostrophecms/login-hcaptcha-stable","name":"@apostrophecms/login-hcaptcha-stable","dist-tags":{"latest":"1.2.1"},"versions":{"1.2.1":{"name":"@apostrophecms/login-hcaptcha-stable","version":"1.2.1","description":"Adds hCaptcha to Apostrophe login pages","main":"index.js","scripts":{"lint":"npm run eslint","eslint":"eslint .","test":"npm run lint && mocha"},"repository":{"type":"git","url":"git+https://github.com/apostrophecms/apostrophe.git","directory":"packages/login-hcaptcha"},"homepage":"https://github.com/apostrophecms/apostrophe/tree/main/packages/login-hcaptcha#readme","keywords":["apostrophecms","captcha","hcaptcha"],"author":{"name":"Apostrophe Technologies"},"license":"MIT","devDependencies":{"apostrophe":"workspace:^","eslint":"^9.39.1","eslint-config-apostrophe":"workspace:^","mocha":"^11.7.5"},"gitHead":"b3e29f004f514041e1e389293ae67017c60d006e","_id":"@apostrophecms/login-hcaptcha-stable@1.2.1","bugs":{"url":"https://github.com/apostrophecms/apostrophe/issues"},"_nodeVersion":"24.10.0","_npmVersion":"11.6.1","dist":{"integrity":"sha512-Ui1z9E6QgkcptY2p0wCdbVPQ0fvRpY3OWAvKEb5zEluJM9LfcuyoRZ4RBG1vzPL0wRT+owiQBnPxMAKP9CqAUw==","shasum":"fa632490acaa1231f7f0e28c8666ee5a00b288cd","tarball":"https://registry.npmjs.org/@apostrophecms/login-hcaptcha-stable/-/login-hcaptcha-stable-1.2.1.tgz","fileCount":17,"unpackedSize":18215,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDP0xRxC2R/F5rM9wUhiB4j1YJ6hOVpZ7RW2lgUobLdxAiBBorMBwoHH9Ka23azpBClgCQg8HRC75xj3vKtb3uivgw=="}]},"_npmUser":{"name":"boutell","email":"tom@apostrophecms.com"},"directories":{},"maintainers":[{"name":"alexgilbert","email":"alex@apostrophecms.com"},{"name":"boutell","email":"tom@apostrophecms.com"},{"name":"romanek","email":"stuart+npm@apostrophecms.com"},{"name":"bodonkey","email":"robert.means1969+apostrophecms@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/login-hcaptcha-stable_1.2.1_1781112795194_0.32077042009471124"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-10T17:33:14.987Z","1.2.1":"2026-06-10T17:33:15.351Z","modified":"2026-06-10T17:33:15.703Z"},"maintainers":[{"name":"alexgilbert","email":"alex@apostrophecms.com"},{"name":"boutell","email":"tom@apostrophecms.com"},{"name":"romanek","email":"stuart+npm@apostrophecms.com"},{"name":"bodonkey","email":"robert.means1969+apostrophecms@gmail.com"}],"description":"Adds hCaptcha to Apostrophe login pages","homepage":"https://github.com/apostrophecms/apostrophe/tree/main/packages/login-hcaptcha#readme","keywords":["apostrophecms","captcha","hcaptcha"],"repository":{"type":"git","url":"git+https://github.com/apostrophecms/apostrophe.git","directory":"packages/login-hcaptcha"},"author":{"name":"Apostrophe Technologies"},"bugs":{"url":"https://github.com/apostrophecms/apostrophe/issues"},"license":"MIT","readme":"<div align=\"center\">\n  <img src=\"https://raw.githubusercontent.com/apostrophecms/apostrophe/main/logo.svg\" alt=\"ApostropheCMS logo\" width=\"80\" height=\"80\">\n\n  <h1>Apostrophe hCaptcha Login Verification</h1>\n  <p>\n    <a aria-label=\"Apostrophe logo\" href=\"https://v3.docs.apostrophecms.org\">\n      <img src=\"https://img.shields.io/badge/MADE%20FOR%20ApostropheCMS-000000.svg?style=for-the-badge&logo=Apostrophe&labelColor=6516dd\">\n    </a>\n    <a aria-label=\"Test status\" href=\"https://github.com/apostrophecms/login-hcaptcha/actions\">\n      <img alt=\"GitHub Workflow Status (branch)\" src=\"https://img.shields.io/github/workflow/status/apostrophecms/login-hcaptcha/Tests/main?label=Tests&labelColor=000000&style=for-the-badge\">\n    </a>\n    <a aria-label=\"Join the community on Discord\" href=\"http://chat.apostrophecms.org\">\n      <img alt=\"\" src=\"https://img.shields.io/discord/517772094482677790?color=5865f2&label=Join%20the%20Discord&logo=discord&logoColor=fff&labelColor=000&style=for-the-badge&logoWidth=20\">\n    </a>\n    <a aria-label=\"License\" href=\"https://github.com/apostrophecms/login-hcaptcha/blob/main/LICENSE.md\">\n      <img alt=\"\" src=\"https://img.shields.io/static/v1?style=for-the-badge&labelColor=000000&label=License&message=MIT&color=3DA639\">\n    </a>\n  </p>\n</div>\n\nThis login verification module adds a [hCaptcha](https://hcaptcha.com) check when any user logs into the site.\n\n## Installation\n\nTo install the module, use the command line to run this command in an Apostrophe project's root directory:\n\n```\nnpm install @apostrophecms/login-hcaptcha\n```\n\n## Usage\n\nInstantiate the hCaptcha login module in the `app.js` file:\n\n```javascript\nrequire('apostrophe')({\n  shortName: 'my-project',\n  modules: {\n    '@apostrophecms/login-hcaptcha': {}\n  }\n});\n```\n\nThe other requirement is to add your [hCaptcha public API site key](https://docs.hcaptcha.com/configuration#hcaptcha-container-configuration) to the `@apostrophecms/login` module (*not* this module). This module adds functionality to that module (it \"improves\" it, in Apostrophe speak), so most configuration should be directly on the core login module.\n\n\n```javascript\n// modules/@apostrophecms/login/index.js\nmodule.exports = {\n  options: {\n    hcaptcha: {\n      site: 'ADD YOUR SITE KEY',\n      secret: 'ADD YOUR SECRET KEY'\n    }\n  }\n};\n```\n\nOnce configured, hCaptcha verification should work on all login attempts.\n\n### Content security headers\n\nIf your site has a content security policy, including if you use the [Apostrophe Security Headers](https://www.npmjs.com/package/@apostrophecms/security-headers) module, you will need to add additional configuration to use this module. This module adds a script tag to the site's `head` tag fetching hCaptcha code, so we need to allow resources from that domain.\n\n**If you are using the Apostrophe Security Headers module**, add the following policy configuration for that module:\n\n```javascript\nmodule.exports = {\n  options: {\n    policies: {\n      'login-hcaptcha': {\n        'script-src': 'hcaptcha.com *.hcaptcha.com',\n        'frame-src': 'hcaptcha.com *.hcaptcha.com',\n        'style-src': 'hcaptcha.com *.hcaptcha.com',\n        'connect-src': 'hcaptcha.com *.hcaptcha.com'\n      },\n      // Any other policies...\n    }\n  }\n};\n```\n\n**If your content security policy is configured some other way**, add `hcaptcha.com  *.hcaptcha.com` to the `script-src`, `frame-src`, `style-src` and `connect-src` directives.\n\nPlease refer to the list at https://docs.hcaptcha.com/#content-security-policy-settings for any additional settings.\n","readmeFilename":"README.md","_rev":"1-d3eb576d9ccf43cdbf4fe6e9064f0c14"}