Extremely simple, "Good Enough" captcha implemention for flask forms. No server side sessions required.
Project description
Install
pip3 install flask-simple-captcha
or if installing from source
python3 setup.py install
How to use
This package is intended to assign a unique CSRF string per each form submit per user session, without requiring any backend session tracking. First, you'll want to set a variable CAPTCHA_CONFIG['SECRET_CAPTCHA_KEY']
in your app config to a random, complex string. Example: CAPTCHA_CONFIG = {'SECRET_CAPTCHA_KEY':'wMmeltW4mhwidorQRli6Oijuhygtfgybunxx9VPXldz'}
Second, add this to the top of your code.
from flask_simple_captcha import CAPTCHA
CAPTCHA = CAPTCHA(config=config.CAPTCHA_CONFIG)
app = CAPTCHA.init_app(app)
For each route you want captcha protected, add the following code:
@app.route('/example', methods=['GET','POST'])
def example():
if request.method == 'GET':
captcha = CAPTCHA.create()
render_template('example.html', captcha=captcha)
if request.method == 'POST':
c_hash = request.form.get('captcha-hash')
c_text = request.form.get('captcha-text')
if CAPTCHA.verify(c_text, c_hash):
return 'success'
else:
return 'failed captcha'
In the HTML forms you want to generate a captcha: {{ captcha_html(captcha) }}
This will create something like this:
<input type="text" name="captcha-text">
<input type="hidden" name="captcha-hash" value="1o9ig...">
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Hashes for flask-simple-captcha-1.2.0.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | 4ecb4a75ac16be7aa68463c38c9ee4e4e62d7211b15acf961beaf6fea48d983a |
|
MD5 | ba8f42615442f59179e100768ea223fb |
|
BLAKE2b-256 | f2e78f14fc22ec25e27397da4b63896170c0128fc8ebb0fcb815e0a84e2c7f76 |