Download the PHP package cluion/turing without Composer
On this page you can find all versions of the php package cluion/turing. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download cluion/turing
More information about cluion/turing
Files in cluion/turing
Package turing
Short Description Self-hosted, zero-dependency, cross-language modern captcha with a Laravel integration.
License MIT
Homepage https://github.com/cluion/turing
Informations about the package turing
Turing
English · Documentation
A signed challenge the server issues, a client widget that solves it in the browser with native Web Crypto, and a token the enclosing form submits for the server to verify. No external service, no tracking. Three layers: a framework-agnostic PHP Core, framework integrations (Laravel first), and a JS client stack.
Install
Laravel (PHP)
JavaScript
| Package | Install | Use |
|---|---|---|
@cluion/turing-core |
pnpm add @cluion/turing-core |
Headless core (plain / any framework) |
@cluion/turing-element |
pnpm add @cluion/turing-element |
<turing-captcha> Web Component |
@cluion/turing-vue |
pnpm add @cluion/turing-vue |
<Turing> Vue 3 component |
@cluion/turing-react |
pnpm add @cluion/turing-react |
<Turing/> React component |
Plain HTML via CDN — pin an exact version and add Subresource Integrity:
Usage
Laravel — one line to show, one line to verify
The <x-turing/> component renders a CSP-safe container the client widget mounts
onto. The widget fetches the challenge from data-turing-url, solves the PoW
with native Web Crypto (no WASM), and injects a hidden turing_token for the
form to submit.
JavaScript
A runnable plain-HTML page is in
examples/plain-html/index.html. Framework
guides: Plain HTML
· React ·
Security.
Core
Framework-agnostic PHP core under php/src/Core. Token =
base64url(payload).base64url(signature) with canonical (sorted-key) JSON.
HMAC-SHA256 default signing (Ed25519 opt-in). Challenge types: math, text,
pow (PBKDF2-SHA256 default, SHA-256 leading-zero-bit opt-in). Stateless by
default; single-use via a Store.
Cross-language vectors
php/tests/vectors/ is the wire contract — the
authoritative wire-contract reference quotes
them verbatim (a docs build guard fails on drift). Language ports MUST reproduce
these fixtures exactly (token bytes, PoW counters, answer hashes). Binary payload
fields (e.g. keySignature) are always base64url of the raw bytes.
Development
License
MIT.
All versions of turing with dependencies
ext-json Version *
ext-mbstring Version *
ext-hash Version *
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0