mirror of
https://github.com/mCaptcha/mCaptcha.git
synced 2025-03-15 05:28:27 +03:00
SUMMARY At present, sitekey can be abused by installing it on a third-party site as verifying the access token returned from CAPTCHA validation doesn't require any authentication. This fix uses account secret authentication to verify access tokens credits: by @gusted |
||
---|---|---|
.. | ||
db-core | ||
db-migrations | ||
db-sqlx-postgres |