Skip to main content

Extremely simple, "Good Enough" captcha implemention for flask forms. No server side sessions required.

Project description

flask-simple-captcha

CURRENT VERSION: v4.1.2

flask-simple-captcha is a robust CAPTCHA generator class for generating and validating CAPTCHAs. It allows for easy integration into Flask applications.

Features

  • Generates CAPTCHAs with customizable length and characters
  • Easy integration with Flask applications
  • Built-in image rendering and line drawing for added complexity
  • Base64 image encoding for easy embedding into HTML
  • JWT-based verification for secure CAPTCHA checks
  • Successfully submitted CAPTCHAs are stored in-memory to prevent resubmission
  • Backwards compatible with 1.0 versions of this package

Prerequisites

  • Python 3.7 or higher
  • Pillow library for image manipulation

Installation

Import this package directly into your Flask project and make sure to install all dependencies.

How to Use

Configuration

DEFAULT_CONFIG = {
    'SECRET_CAPTCHA_KEY': 'CHANGEME - 40 or 50 character long key here',
    'CAPTCHA_LENGTH': 6,
    'CAPTCHA_DIGITS': False,
    # 'EXPIRE_MINUTES': 10,
    'UNIQUE_SALT_LENGTH': 16,
    # 10 minutes, EXPIRE_SECONDS will take prioritity over EXPIRE_MINUTES
    # if both are set.
    'EXPIRE_SECONDS': 60 * 10,
}

# Normalize jwt expiration time to seconds
if 'EXPIRE_NORMALIZED' not in DEFAULT_CONFIG:
    EXPIRE_NORMALIZED = DEFAULT_CONFIG.get('EXPIRE_SECONDS', 60 * 10)
    DEFAULT_CONFIG['EXPIRE_NORMALIZED'] = EXPIRE_NORMALIZED

Initialization

Add this code snippet at the top of your application:

from flask_simple_captcha import CAPTCHA
SIMPLE_CAPTCHA = CAPTCHA(config=config.CAPTCHA_CONFIG)
app = SIMPLE_CAPTCHA.init_app(app)

Protecting a Route

To add CAPTCHA protection to a route, you can use the following code:

@app.route('/example', methods=['GET','POST'])
def example():
    if request.method == 'GET':
        new_captcha_dict = SIMPLE_CAPTCHA.create()
        render_template('example.html', captcha=new_captcha_dict)
    if request.method == 'POST':
        c_hash = request.form.get('captcha-hash')
        c_text = request.form.get('captcha-text')
        if SIMPLE_CAPTCHA.verify(c_text, c_hash):
            return 'success'
        else:
            return 'failed captcha'

In your HTML template, you need to wrap the CAPTCHA inputs within a form element. The package will only generate the CAPTCHA inputs but not the surrounding form or the submit button.

<!-- your_template.html -->
<form action="/example" method="post">
  {{ captcha_html(captcha)|safe }}
  <input type="submit" value="Submit">
</form>

Debugging

You can run debug_flask_server.py for minimal testing on port 5000. This allows you to test the generated CAPTCHA HTML and submission behavior.

# Might want to use venv
pip3 install -r requirements_dev.txt

python3 debug_flask_server.py

Running Tests

  1. Install the development requirements:
pip install -r requirements_dev.txt
  1. Run the tests:
python3 tests.py

or

python3 -m unittest tests.py

Contributing

Feel free to open a PR. The project has undergone a recent overhaul to improve the code quality.

License

MIT

Contact: ccarterdev@gmail.com

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

flask-simple-captcha-4.1.2.tar.gz (207.5 kB view hashes)

Uploaded Source

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page