Download the PHP package watsonhaw/think-captcha without Composer

On this page you can find all versions of the php package watsonhaw/think-captcha. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package think-captcha

think-captcha

ThinkPHP 验证码扩展

本扩展提供 两种验证码实现,按你的项目场景选择:

类 存储策略 适用场景
CaptchaService(推荐) Cache + Key 前后端分离、跨域、SPA、小程序、App、分布式多节点
Captcha(传统类) Session 单体项目、传统服务端渲染、和 ThinkPHP Session 深度绑定

CaptchaService 只做三件事 —— 生成、校验、删除 —— 返回纯数据,路由 / 响应格式 / CORS / 限流 均由你在业务控制器里自行掌控,灵活度最高。


安装

环境要求:

  • PHP >= 7.4(推荐 PHP 8+)
  • 启用 GD 扩展(ext-gd)、Mbstring(ext-mbstring)
  • ThinkPHP 6.0 / 8.0 通用

安装后会自动注册服务(extra.think),配置文件会被发布到 config/captcha.php。


5 分钟上手

1. 在你自己的业务控制器里写两个方法

2. 在登录/注册等接口里校验

3. 前端(Vue / Axios 示例)


三种调用风格,任挑一种(均走 CaptchaService 底层)

✅ 静态类(推荐,最清晰)

✅ Facade

✅ 助手函数


传统 Captcha 类用法(Session 存储,单体项目)

如果你的项目是传统 MVC + Session,不做前后端分离,可以直接使用原版风格的 Captcha 类(配合 ThinkPHP Container 自动注入):

💡 传统 Captcha 类额外支持:中文验证码、背景透明度 alpha、指定字体文件 fontttf、API 模式(返回 [code+img] 数组) 等特性,详见下文配置对比表。


配置(config/captcha.php)

全部配置项速查(两个类都支持的 12 项)

⚠️ 两个实现类的配置支持差异

参数 CaptchaService(推荐) Captcha(传统 Session 类) 备注
length ✅ 支持,下限 1 ✅ 支持 -
codeSet ✅ 空串自动回退默认 ✅ 支持 -
expire ✅ 作为 Cache TTL,下限 10s ✅ 配置读取但实际未使用(依赖 PHP Session 过期) ⚠️ Captcha 类 expire 字段是"假支持"
math ✅ + / - / × 三种运算 ✅ 仅支持 + 加法 ⚠️ 两者算法不同
useNoise ✅ 按面积计算干扰点密度 ✅ 调用 writeNoise() -
useCurve ✅ 两段贝塞尔风格折线 ✅ 正弦函数曲线 视觉效果不同
useImgBg ✅ JPG / PNG / GIF 均可 ✅ 仅支持 JPG ⚠️ Captcha 放 PNG/GIF 会被静默忽略
bg ✅ 少于 3 项自动回退 ✅ 支持 -
imageH ✅ 自动计算 + 下限 24px ✅ 自动计算 公式不同
imageW ✅ 自动计算 + 下限 60px ✅ 自动计算 公式不同
fontSize ✅ 下限 10px ✅ 支持 -
cachePrefix ✅ Cache Key 前缀 ❌ 不使用(用 Session) -

🔧 Captcha 类额外独有的配置项(config/captcha.php 可追加)

以下 6 项只有传统 Captcha 类会读取,CaptchaService 不支持:

🎯 场景化子配置示例(login / register 分组)

CaptchaService::generate('login') / captcha_generate('register') 会自动合并二级数组:


设计说明

关注点 做法
前后端解耦 不使用 Session,改为 Cache 存验证码,用 key 关联;图片直接返回 data:image/png;base64
一次性 校验通过后自动从 Cache 删除,防重放
分布式 只要 TP 项目的 cache.php 配的是共享缓存(Redis/Memcached),任意节点都能校验
无副作用 CaptchaService 不注册路由、不发响应、不加 CORS 头,完全不侵入项目结构
安全 用户输入与缓存值做 大小写不敏感 比对,体验更友好
图片资源 优先使用 assets/ttfs 下的 TTF/OTF 字体(中文则用 assets/zhttfs),找不到自动降级到 GD 内置字体

旧函数兼容性(从原版 think-captcha 升级的同学看这里)

原版 captcha() / captcha_check() / captcha_src() / captcha_img() 依然可用,只是底层换成了 CaptchaService:

⚠️ captcha_src() / captcha_img() 依赖你自己注册 /captcha/[:config] 路由(本扩展不再自动注册)。


常见问题

Q: 为什么不直接把验证码字符串塞到响应里? A: 那等于把答案告诉前端,完全失去校验意义。所以前端只拿 图片 + key,key 只是一个随机索引,不包含答案信息。

Q: 刷新时旧 key 的验证码还能被撞库吗? A: 调 CaptchaService::remove($oldKey) 就会立刻失效;不调的话等到 expire 秒后缓存也会自动过期。

Q: 支持中文验证码吗? A: ✅ 两个类都内置中文字体。使用方式不同:

Q: useImgBg=true 放了 PNG 背景为什么没生效? A: 传统 Captcha 类只支持 JPG(background() 里写死 substr($file,-4) == '.jpg'),放 PNG/GIF 会静默降级到纯色 bg;改用 CaptchaService 类即支持 JPG/PNG/GIF 三种。

Q: math=true 为什么 Captcha 和 CaptchaService 出来的不一样? A: 两者算法独立实现:传统 Captcha 只有 X + Y = 加法;CaptchaService 会随机出 + / - / ×,且会自动把减法调成非负数、乘法控制在 1-5 防答案过大。

Q: 验证码存储在 Cache/Session 会不会泄露? A: 不会。存的不是明文,Captcha 用 password_hash() 加盐 bcrypt 哈希;CaptchaService 虽然存明文小写字符串,但 key 是 md5(uniqid+mt_rand) 的随机串,暴力猜对 key 的概率忽略不计,而且校验通过后会立即删除(一次性)。


开发 & 贡献

本仓库自带完整的 PHPUnit 12 单元测试、PHPStan 静态分析、PHP-CS-Fixer 代码风格检查。

测试覆盖范围:


All versions of think-captcha with dependencies

PHP Build Version
Package Version
Requires ext-gd Version *
ext-mbstring Version *
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package watsonhaw/think-captcha contains the following files

Loading the files please wait ...