2026-09-29 11:23:57 +08:00
2026-09-12 10:38:55 +08:00
2026-09-12 08:14:34 +08:00
2026-09-12 10:46:36 +08:00

CaptchaKit

CaptchaKit is an ASP.NET Core CAPTCHA foundation with server-side, one-time validation and pluggable generators and storage.

CaptchaKit.Core has provider-neutral contracts. CaptchaKit.AspNetCore supplies randomized distorted-text, image-math, and image-target-selection challenges with IDistributedCache storage.

The package does not claim that image CAPTCHA alone defeats determined automation. Deploy it with rate limits, account lockout, and appropriate risk controls.

Quick start

Install both packages at the same version:

dotnet add package CaptchaKit.AspNetCore --prerelease

Configure a distributed cache (Redis is recommended for more than one application instance), then add the service:

builder.Services.AddStackExchangeRedisCache(options =>
    options.Configuration = builder.Configuration.GetConnectionString("Redis"));
builder.Services.AddCaptchaKit(options =>
{
    options.CodeLength = 5;
    options.Lifetime = TimeSpan.FromMinutes(2);
    options.CacheKeyPrefix = "myapp:captcha:";
});

An endpoint can obtain a challenge and return its type, prompt, choices, and optional image in the format used by its UI:

var challenge = await captcha.CreateAsync(cancellationToken);
var imageData = $"data:{challenge.ContentType};base64,{Convert.ToBase64String(challenge.ImageBytes)}";

Before completing the protected action, validate it once:

if (!await captcha.VerifyAsync(request.CaptchaId, request.CaptchaCode, cancellationToken))
    return Results.Unauthorized();

VerifyAsync consumes the challenge on every attempt. Applications can replace ICaptchaGenerator or ICaptchaChallengeStore to use another challenge type or persistence backend.

S
Description
No description provided
Readme MIT
390 KiB
0 Stars 1 Watchers 0 Forks
Languages
C# 100%