gate locale behind functional consent

This commit is contained in:
2026-08-12 18:03:11 +02:00
parent 195d4169f5
commit 4bf50514bf
212 changed files with 173 additions and 840 deletions
-12
View File
@@ -1,12 +0,0 @@
/**
* Cloudflare Turnstile widget — reusable across any form. Renders the challenge
* and reports the token via onToken. The token must then be verified
* server-side (see verifyTurnstile) before a submission is trusted.
*
* siteKey is a prop rather than an env var so all Turnstile config lives in one
* place (SiteIntegrations), consistent with the plugin's panel-managed model.
* The script is injected directly (no next/script dependency) so the widget
* stays framework-agnostic.
*/ export { };
//# sourceMappingURL=Turnstile.d.js.map
-1
View File
@@ -1 +0,0 @@
{"version":3,"sources":["Turnstile.d.ts"],"sourcesContent":["declare global {\n interface Window {\n turnstile?: {\n render: (el: HTMLElement, opts: Record<string, unknown>) => string;\n reset: (id?: string) => void;\n };\n }\n}\nexport type TurnstileProps = {\n /** Called with the token once solved, or null on expiry/error. */\n onToken: (token: null | string) => void;\n /**\n * Public Turnstile site key. The client project reads it server-side from\n * SiteIntegrations (turnstileSiteKey) and passes it in — the widget is a pure\n * client component and can't read Payload itself.\n */\n siteKey: string;\n theme?: 'auto' | 'dark' | 'light';\n};\n/**\n * Cloudflare Turnstile widget — reusable across any form. Renders the challenge\n * and reports the token via onToken. The token must then be verified\n * server-side (see verifyTurnstile) before a submission is trusted.\n *\n * siteKey is a prop rather than an env var so all Turnstile config lives in one\n * place (SiteIntegrations), consistent with the plugin's panel-managed model.\n * The script is injected directly (no next/script dependency) so the widget\n * stays framework-agnostic.\n */\nexport declare function Turnstile({ onToken, siteKey, theme }: TurnstileProps): import(\"react/jsx-runtime\").JSX.Element | null;\n"],"names":[],"mappings":"AAmBA;;;;;;;;;CASC,GACD,WAA+H"}
-3
View File
@@ -1,3 +0,0 @@
export { Turnstile } from './Turnstile.js';
//# sourceMappingURL=client.d.js.map
-1
View File
@@ -1 +0,0 @@
{"version":3,"sources":["client.d.ts"],"sourcesContent":["export { Turnstile } from './Turnstile.js';\nexport type { TurnstileProps } from './Turnstile.js';\n"],"names":["Turnstile"],"mappings":"AAAA,SAASA,SAAS,QAAQ,iBAAiB"}
-3
View File
@@ -1,3 +0,0 @@
export { verifyTurnstile } from './verify.js';
//# sourceMappingURL=index.d.js.map
-1
View File
@@ -1 +0,0 @@
{"version":3,"sources":["index.d.ts"],"sourcesContent":["export { verifyTurnstile } from './verify.js';\n"],"names":["verifyTurnstile"],"mappings":"AAAA,SAASA,eAAe,QAAQ,cAAc"}
-3
View File
@@ -1,3 +0,0 @@
import 'server-only';
//# sourceMappingURL=verify.d.js.map
-1
View File
@@ -1 +0,0 @@
{"version":3,"sources":["verify.d.ts"],"sourcesContent":["import 'server-only';\nimport type { BasePayload } from 'payload';\ntype VerifyTurnstileArgs = {\n /** Optional client IP for stricter verification. */\n ip?: string;\n /** Payload instance — used to read the secret from SiteIntegrations. */\n payload: BasePayload;\n /** Token produced by the client-side widget. */\n token: string;\n};\n/**\n * Verifies a Turnstile token with Cloudflare, server-side only.\n *\n * The secret comes from the SiteIntegrations global (editor-managed, per the\n * plugin's \"secrets in the panel\" model), read via the Local API which bypasses\n * access control. `server-only` guarantees this never reaches the browser\n * bundle, keeping the secret off the client.\n *\n * Returns false on any failure (missing secret/token, network error, rejected\n * challenge) — callers treat false as \"do not trust this submission\".\n */\nexport declare function verifyTurnstile({ ip, payload, token, }: VerifyTurnstileArgs): Promise<boolean>;\nexport {};\n"],"names":[],"mappings":"AAAA,OAAO,cAAc"}