Tags: dereuromark/cakephp-captcha
Tags
docs: Fix formatting of passiveClass section (#58) The section added in #57 lost its code fences, so the PHP config array and the CSS rule render as prose on GitHub. Also: - `style-src: unsafe-inline` is not valid CSP syntax; inline style attributes are governed by `'unsafe-inline'` in `style-src` / `style-src-attr`. - Note that the class has to hide the field from assistive technology, not just visually. An off-screen-only class (`.sr-only`, `.visually-hidden`) would let screen reader users fill in the honeypot and get rejected.
feat: Add passiveClass config option to avoid inline style (CSP compa… …tibility) (#57) * feat: Add passiveClass config option to avoid inline style (CSP compatibility) ## Problem The `passive()` method renders the honeypot div with `style="display: none"`, which violates a strict Content-Security-Policy (`style-src` without `unsafe-inline`). ## Solution Add an optional `passiveClass` config key. When set, the wrapper `<div>` uses a CSS class instead of the inline style, enabling e.g. Bootstrap's `d-none`: Configure::write('Captcha', ['passiveClass' => 'd-none']); Default is `null`, preserving the existing behavior — fully backward compatible. ## Use case Any application with a strict CSP that forbids `style-src: unsafe-inline` (e.g. using a Content-Security-Policy header or meta tag) currently cannot use `passive()` without a CSP violation. ## Configuration `Configure::write('Captcha', ['passiveClass' => 'd-none']);` in `config/app_local.php` or via helper-config: `$this->loadHelper('Captcha.Captcha', ['passiveClass' => 'd-none'])` * feat: Add passiveClass * Fix coding standard (tabs indentation) --------- Co-authored-by: Mark Scherer <dereuromark@users.noreply.github.com>
PreviousNext