Download the PHP package rasuvaeff/yii3-turnstile without Composer
On this page you can find all versions of the php package rasuvaeff/yii3-turnstile. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download rasuvaeff/yii3-turnstile
More information about rasuvaeff/yii3-turnstile
Files in rasuvaeff/yii3-turnstile
Package yii3-turnstile
Short Description Cloudflare Turnstile CAPTCHA widget and validator for Yii3.
License BSD-3-Clause
Homepage https://github.com/rasuvaeff/yii3-turnstile
Informations about the package yii3-turnstile
rasuvaeff/yii3-turnstile
Cloudflare Turnstile CAPTCHA widget and server-side validator for Yii3.
Provides a Turnstile widget for rendering the challenge in a form and a
TurnstileRule / TurnstileRuleHandler pair for server-side verification through
the Yii validator pipeline. HTTP calls go through any PSR-18 client.
Using an AI coding assistant? llms.txt contains a compact API reference you can share with the model. Contributors: see AGENTS.md.
Requirements
| Requirement | Version |
|---|---|
| PHP | ^8.3 |
| A PSR-18 HTTP client + PSR-17 factories | any implementation |
yiisoft/widget |
^2.2 |
yiisoft/html |
^3.13 || ^4.0 |
yiisoft/validator |
^2.5 |
yiisoft/translator |
^3.0 |
yiisoft/request-provider |
^1.3 |
Installation
You also need a PSR-18 client and PSR-17 factories if your project doesn't already ship one:
DI configuration
Since v1.0.3 the package ships config/bootstrap.php via config-plugin. On every
application boot it populates TurnstileRegistry with the handler dependencies, so
TurnstileRuleHandler works even with the default SimpleRuleHandlerContainer —
no extra DI config required.
If your app already uses RuleHandlerContainer for other reasons, keep it; this
package is compatible with both resolvers.
Usage
1. Render the widget in a form
Output:
2. Validate server-side with a validator rule
Field name mapping with Yii3 FormModel
Cloudflare's widget submits the token as
cf-turnstile-response(with hyphens) by default. PHP does not normalize hyphens in POST keys, so setwithResponseFieldName()to a PHP-compatible name that matches your model property:
The rule sends the token to Cloudflare's siteverify endpoint and reports
success/failure through the standard Yii validator Result.
3. Dependency injection (Yii3)
The package ships config/params.php and config/di.php compatible with
yiisoft/config. Override params in your application config:
The DI config registers a CategorySource tagged as translation.categorySource.
When yiisoft/translator-message-php is installed, it reads message files from
messages/<locale>/yii3-turnstile.php. Without it, message IDs are returned as-is.
4. Translations
The package includes Russian translations out of the box:
| Locale | File |
|---|---|
ru |
messages/ru/yii3-turnstile.php |
To add more languages, create messages/<locale>/yii3-turnstile.php:
Components
Turnstile (widget)
Renders the Cloudflare Turnstile HTML + script tag. Extends Yiisoft\Widget\Widget.
| Method | Description |
|---|---|
withSiteKey(string $siteKey): self |
Cloudflare site key (required). |
withTheme(TurnstileTheme $theme): self |
Auto, Light, or Dark. Default: Auto. |
withSize(TurnstileSize $size): self |
Normal, Compact, Flexible, or Invisible. Default: Normal. |
withResponseFieldName(string $name): self |
Name of the hidden input field. Default: cf-turnstile-response. |
withJsApiUrl(string $url): self |
Override the script URL. Default: Cloudflare CDN. |
render(): string |
Returns the HTML string. Throws if siteKey is not set. |
TurnstileConfig
Immutable configuration DTO.
TurnstileClient
Sends the token verification POST to Cloudflare. Requires PSR-18 + PSR-17.
idempotencyKey is an optional UUID that lets you safely re-verify the same
token (Cloudflare returns the original result instead of an error); it is only
sent when provided. verifyWithSecret() is used by the rule handler when a
per-rule secret override is set.
VerificationResult
DTO returned by TurnstileClient::verify().
TurnstileRule / TurnstileRuleHandler
A RuleInterface for the Yii validator. The handler receives TurnstileClient
from DI and calls verify() with the token value. When sendRemoteIp is set,
the handler reads the client IP from the current request via
yiisoft/request-provider (RequestProviderInterface::get(), REMOTE_ADDR
server param); if no request is set the IP is simply omitted. Supports
skipOnEmpty, skipOnError, and when via standard validator traits.
| Method | Description |
|---|---|
getHandler(): string |
Returns TurnstileRuleHandler::class. |
getMessage(): string |
Error message on failure. |
getSecret(): ?string |
Override secret (uses DI config if null). |
getSendRemoteIp(): bool |
Whether to forward client IP. |
Enums
| Enum | Values |
|---|---|
TurnstileTheme |
`A |
t}o,Light,Dark` |
|
TurnstileSize |
Normal, Compact, Flexible, Invisible |
Security
- The widget renders a public site key in HTML — this is intentional and safe.
- The secret is only used server-side in
TurnstileClientand never reaches the browser. - Token verification goes over HTTPS to Cloudflare's
siteverifyendpoint. sendRemoteIpis opt-in (disabled by default); the client IP is taken from the current request viaRequestProviderInterface(REMOTE_ADDR), not from user input.
Examples
See examples/ for runnable scripts.
| Script | Shows | Needs server? |
|---|---|---|
widget.php |
Rendering the Turnstile widget | no |
verify.php |
Server-side token verification | no |
Development
No PHP/Composer on the host — run in Docker via the composer:2 image:
Or with Make:
CI runs composer build on PHP 8.3, 8.4, and 8.5.
License
BSD-3-Clause
All versions of yii3-turnstile with dependencies
psr/http-client Version ^1.0
psr/http-factory Version ^1.0
psr/http-message Version ^1.0 || ^2.0
yiisoft/html Version ^3.13 || ^4.0
yiisoft/request-provider Version ^1.3
yiisoft/translator Version ^3.0
yiisoft/validator Version ^2.5
yiisoft/widget Version ^2.2