Files
ipal-kit/dist/modules/turnstile/verify.d.ts
T
2026-07-31 23:21:51 +02:00

24 lines
976 B
TypeScript

import 'server-only';
import type { BasePayload } from 'payload';
type VerifyTurnstileArgs = {
/** Optional client IP for stricter verification. */
ip?: string;
/** Payload instance — used to read the secret from SiteIntegrations. */
payload: BasePayload;
/** Token produced by the client-side widget. */
token: string;
};
/**
* Verifies a Turnstile token with Cloudflare, server-side only.
*
* The secret comes from the SiteIntegrations global (editor-managed, per the
* plugin's "secrets in the panel" model), read via the Local API which bypasses
* access control. `server-only` guarantees this never reaches the browser
* bundle, keeping the secret off the client.
*
* Returns false on any failure (missing secret/token, network error, rejected
* challenge) — callers treat false as "do not trust this submission".
*/
export declare function verifyTurnstile({ ip, payload, token, }: VerifyTurnstileArgs): Promise<boolean>;
export {};