24 lines
976 B
TypeScript
24 lines
976 B
TypeScript
import 'server-only';
|
|
import type { BasePayload } from 'payload';
|
|
type VerifyTurnstileArgs = {
|
|
/** Optional client IP for stricter verification. */
|
|
ip?: string;
|
|
/** Payload instance — used to read the secret from SiteIntegrations. */
|
|
payload: BasePayload;
|
|
/** Token produced by the client-side widget. */
|
|
token: string;
|
|
};
|
|
/**
|
|
* Verifies a Turnstile token with Cloudflare, server-side only.
|
|
*
|
|
* The secret comes from the SiteIntegrations global (editor-managed, per the
|
|
* plugin's "secrets in the panel" model), read via the Local API which bypasses
|
|
* access control. `server-only` guarantees this never reaches the browser
|
|
* bundle, keeping the secret off the client.
|
|
*
|
|
* Returns false on any failure (missing secret/token, network error, rejected
|
|
* challenge) — callers treat false as "do not trust this submission".
|
|
*/
|
|
export declare function verifyTurnstile({ ip, payload, token, }: VerifyTurnstileArgs): Promise<boolean>;
|
|
export {};
|