{"_id":"@apostrophecms/login-recaptcha-stable","name":"@apostrophecms/login-recaptcha-stable","dist-tags":{"latest":"1.2.0"},"versions":{"1.2.0":{"name":"@apostrophecms/login-recaptcha-stable","version":"1.2.0","description":" Adds reCAPTCHA v3 to Apostrophe login pages","main":"index.js","scripts":{"lint":"npm run eslint && npm run stylelint","eslint":"eslint .","stylelint":"stylelint ui/**/*.{scss,vue}","test":"npm run lint && mocha"},"repository":{"type":"git","url":"git+https://github.com/apostrophecms/apostrophe.git","directory":"packages/login-recaptcha"},"homepage":"https://github.com/apostrophecms/apostrophe/tree/main/packages/login-recaptcha#readme","author":{"name":"Apostrophe Technologies"},"license":"MIT","devDependencies":{"apostrophe":"workspace:^","eslint":"^9.39.1","eslint-config-apostrophe":"workspace:^","mocha":"^11.7.5","stylelint":"^16.0.0","stylelint-config-apostrophe":"workspace:^"},"gitHead":"b3e29f004f514041e1e389293ae67017c60d006e","_id":"@apostrophecms/login-recaptcha-stable@1.2.0","bugs":{"url":"https://github.com/apostrophecms/apostrophe/issues"},"_nodeVersion":"24.10.0","_npmVersion":"11.6.1","dist":{"integrity":"sha512-l0f7MJiUGr6aUo8doZZ8UsUUKhBtSZp3PUabtHAHuwcL16JUwvGBjS6NzBcuA36Fuedd1EiND7CcBdw1y/otfg==","shasum":"10b6710c2d79cbf9b9ef6db6c291fa50b4d597fb","tarball":"https://registry.npmjs.org/@apostrophecms/login-recaptcha-stable/-/login-recaptcha-stable-1.2.0.tgz","fileCount":12,"unpackedSize":16193,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDqSdyLQgNV8CNJKCz+b0Yc0v0yuym1PTH/AHuRTGUDlAiEAyP2edYA0nhQ8yxDWv0apxfuTRyvMdNrNXKFhN/hTkyg="}]},"_npmUser":{"name":"boutell","email":"tom@apostrophecms.com"},"directories":{},"maintainers":[{"name":"alexgilbert","email":"alex@apostrophecms.com"},{"name":"boutell","email":"tom@apostrophecms.com"},{"name":"romanek","email":"stuart+npm@apostrophecms.com"},{"name":"bodonkey","email":"robert.means1969+apostrophecms@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/login-recaptcha-stable_1.2.0_1781112797747_0.926426169914186"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-10T17:33:17.520Z","1.2.0":"2026-06-10T17:33:17.931Z","modified":"2026-06-10T17:33:18.310Z"},"maintainers":[{"name":"alexgilbert","email":"alex@apostrophecms.com"},{"name":"boutell","email":"tom@apostrophecms.com"},{"name":"romanek","email":"stuart+npm@apostrophecms.com"},{"name":"bodonkey","email":"robert.means1969+apostrophecms@gmail.com"}],"description":" Adds reCAPTCHA v3 to Apostrophe login pages","homepage":"https://github.com/apostrophecms/apostrophe/tree/main/packages/login-recaptcha#readme","repository":{"type":"git","url":"git+https://github.com/apostrophecms/apostrophe.git","directory":"packages/login-recaptcha"},"author":{"name":"Apostrophe Technologies"},"bugs":{"url":"https://github.com/apostrophecms/apostrophe/issues"},"license":"MIT","readme":"<div align=\"center\">\n  <img src=\"https://raw.githubusercontent.com/apostrophecms/apostrophe/main/logo.svg\" alt=\"ApostropheCMS logo\" width=\"80\" height=\"80\">\n\n  <h1>Apostrophe reCAPTCHA Login Verification</h1>\n  <p>\n    <a aria-label=\"Apostrophe logo\" href=\"https://v3.docs.apostrophecms.org\">\n      <img src=\"https://img.shields.io/badge/MADE%20FOR%20ApostropheCMS-000000.svg?style=for-the-badge&logo=Apostrophe&labelColor=6516dd\">\n    </a>\n    <a aria-label=\"Test status\" href=\"https://github.com/apostrophecms/login-recaptcha/actions\">\n      <img alt=\"GitHub Workflow Status (branch)\" src=\"https://img.shields.io/github/workflow/status/apostrophecms/login-recaptcha/Tests/main?label=Tests&labelColor=000000&style=for-the-badge\">\n    </a>\n    <a aria-label=\"Join the community on Discord\" href=\"http://chat.apostrophecms.org\">\n      <img alt=\"\" src=\"https://img.shields.io/discord/517772094482677790?color=5865f2&label=Join%20the%20Discord&logo=discord&logoColor=fff&labelColor=000&style=for-the-badge&logoWidth=20\">\n    </a>\n    <a aria-label=\"License\" href=\"https://github.com/apostrophecms/login-recaptcha/blob/main/LICENSE.md\">\n      <img alt=\"\" src=\"https://img.shields.io/static/v1?style=for-the-badge&labelColor=000000&label=License&message=MIT&color=3DA639\">\n    </a>\n  </p>\n</div>\n\nThis login verification module adds a [reCAPTCHA](https://developers.google.com/recaptcha/intro) check when any user logs into the site. It uses reCAPTCHA v3, which means that the test is invisible aside from a reCAPTCHA logo at the bottom of the screen.\n\n## Installation\n\nTo install the module, use the command line to run this command in an Apostrophe project's root directory:\n\n```\nnpm install @apostrophecms/login-recaptcha\n```\n\n## Usage\n\nInstantiate the reCAPTCHA login module in the `app.js` file:\n\n```javascript\nrequire('apostrophe')({\n  shortName: 'my-project',\n  modules: {\n    '@apostrophecms/login-recaptcha': {}\n  }\n});\n```\n\nThe other requirement is to add [reCAPTCHA site and secret keys](https://developers.google.com/recaptcha/intro#recaptcha-overview) to the `@apostrophecms/login` module (*not* this module). This module adds functionality to that module (it \"improves\" it, in Apostrophe speak), so most configuration should be directly on the core login module.\n\n\n```javascript\n// modules/@apostrophecms/login/index.js\nmodule.exports = {\n  options: {\n    recaptcha: {\n      site: 'ADD YOUR SITE KEY',\n      secret: 'ADD YOUR SECRET KEY'\n    }\n  }\n};\n```\n\nOnce configured, reCAPTCHA verification should work on all login attempts.\n\n### Content security headers\n\nIf your site has a content security policy, including if you use the [Apostrophe Security Headers](https://www.npmjs.com/package/@apostrophecms/security-headers) module, you will need to add additional configuration to use this module. This module adds a script tag to the site's `head` tag fetching reCAPTCHA code. That reCAPTCHA code also constructs an iframe. The external script and iframe use the `www.google.com` and `www.gstatic.com` domains, so we need to allow resources from that domain.\n\n**If you are using the Apostrophe Security Headers module**, add the following policy configuration for that module:\n\n```javascript\nmodule.exports = {\n  options: {\n    policies: {\n      'login-recaptcha': {\n        'script-src': 'www.google.com www.gstatic.com',\n        'frame-src': 'www.google.com'\n      },\n      // Any other policies...\n    }\n  }\n};\n```\n\n**If your content security policy is configured some other way**, add `www.google.com` to the `frame-src` directive and  `www.google.com www.gstatic.com` to the `script-src` directive.\n","readmeFilename":"README.md","_rev":"1-3421f19e9e8737b846c4360a3d082f44"}