fix(backend): prevent login block when captcha enabled without cloudflare key (#194)

When captcha_enabled=true but cloudflare_secret_key is not configured,
the login flow would block users with "未配置Cloudflare Site Key" error.
Now captcha is treated as disabled if the secret key is missing, allowing
users to log in normally on fresh PostgreSQL installations.

Fixes login issue on new panel setups with PostgreSQL.
This commit is contained in:
sagit
2026-02-22 22:54:51 +08:00
committed by GitHub
parent bb505d461d
commit 61690f5bb1
+13 -2
View File
@@ -988,10 +988,21 @@ func (h *Handler) captchaEnabled() (bool, error) {
if err != nil {
return false, err
}
if cfg == nil {
if cfg == nil || !strings.EqualFold(cfg.Value, "true") {
return false, nil
}
return strings.EqualFold(cfg.Value, "true"), nil
// captcha_enabled=true, but we need to verify cloudflare_secret_key is configured
// If secret key is not configured, treat captcha as disabled to avoid blocking login
secretKey, err := h.repo.GetConfigByName("cloudflare_secret_key")
if err != nil {
return false, err
}
if secretKey == nil || strings.TrimSpace(secretKey.Value) == "" {
return false, nil
}
return true, nil
}
func (h *Handler) markCaptchaToken(token string) {