Skip to main content
Odoo Community Association

Privacy Friendly Captcha

Beta License: AGPL-3 OCA/website Translate me on Weblate Try me on Runboat

This module allows to use a Captcha System completly handled by Odoo.

It relies on Altcha (https://altcha.org), an OpenSource captcha alternative.

Table of contents

Use Cases / Context

Currently, Odoo provides 2 options:

  • Google Recaptcha relies on tracking of the user. It implies cookies

  • Cloudfare Turnstile relies on signals of the browser so it is less GDPR problematic. However, it relies on a third party infrastructure. The decision is made from a probabilistic perspective (likely a human)

With this new module, everything relies on our own system with no cookies, no tracking and no network calls.

The way to solve it is to add a deterministic puzzle to solve. Bots need to spend more CPU, making it costly at scale.

Configuration

Go to Configuration/Website, check “Enable Altcha” under “Privacy”. Some extra parameters will appear with all the ALTCHA information. This parameters are website dependent.

  • altcha_key: This key is made to create the challenge and review it later

Also, the system adds the option to use some extra parameters:

  • altcha_secret_key: Key used to use deterministic mode. Using it will make it faster from a server perspective.

  • altcha_algorithm: Algorithm used, by default PBKDF2/SHA-512, however, we can use:

    • Fast ones only for testing purposes: SHA-256, SHA-384, SHA-512

    • Good by default: PBKDF2/SHA-256, PBKDF2/SHA-384, PBKDF2/SHA-512

    • Memory Hard: SCRYPT. To be implemented

    • Memory Hard (it required argon2-cffi): ARGON2ID. To be implemented

  • altcha_timeout: Number of minutes that we will trust the key, by default 5

  • altcha_cost: Cost of the challenge. By default, 5000

Bug Tracker

Bugs are tracked on GitHub Issues. In case of trouble, please check there if your issue has already been reported. If you spotted it first, help us to smash it by providing a detailed and welcomed feedback.

Do not contact contributors directly about support or help with technical issues.

Credits

Authors

  • Dixmit

Contributors

  • Dixmit

    • Enric Tobella

    • Luís David Rodríguez

Maintainers

This module is maintained by the OCA.

Odoo Community Association

OCA, or the Odoo Community Association, is a nonprofit organization whose mission is to support the collaborative development of Odoo features and promote its widespread use.

Current maintainer:

hbrunn

This module is part of the OCA/website project on GitHub.

You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute.

Release files for odoo-addon-website-altcha 18.0.1.1.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for odoo-addon-website-altcha 18.0.1.1.0.1
File Interpreter ABI Platform
odoo_addon_website_altcha-18.0.1.1.0.1-py3-none-any.whl Python 3 none any Details

Release files / odoo_addon_website_altcha-18.0.1.1.0.1-py3-none-any.whl

Download URL odoo_addon_website_altcha-18.0.1.1.0.1-py3-none-any.whl
Size 115.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
83c8087c1d37b335603fe36cdbd54e41bdb2bfeedb71b2fa4186b7ac1b959892
BLAKE2b-256 checksum
How to use checksums
72700ad2f24f6b325153e327cce0aeca425ee689282b4f9199f10aec47f2db8f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.4
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page