From daf34d0f6cf08a877d40599f75cc385e0c044fc0 Mon Sep 17 00:00:00 2001 From: sagit <36596628+Sagit-chu@users.noreply.github.com> Date: Sun, 22 Feb 2026 22:54:51 +0800 Subject: [PATCH] fix(backend): prevent login block when captcha enabled without cloudflare key (#194) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit When captcha_enabled=true but cloudflare_secret_key is not configured, the login flow would block users with "未配置Cloudflare Site Key" error. Now captcha is treated as disabled if the secret key is missing, allowing users to log in normally on fresh PostgreSQL installations. Fixes login issue on new panel setups with PostgreSQL. --- go-backend/internal/http/handler/handler.go | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/go-backend/internal/http/handler/handler.go b/go-backend/internal/http/handler/handler.go index 9f0fe2b..d588335 100644 --- a/go-backend/internal/http/handler/handler.go +++ b/go-backend/internal/http/handler/handler.go @@ -988,10 +988,21 @@ func (h *Handler) captchaEnabled() (bool, error) { if err != nil { return false, err } - if cfg == nil { + if cfg == nil || !strings.EqualFold(cfg.Value, "true") { return false, nil } - return strings.EqualFold(cfg.Value, "true"), nil + + // captcha_enabled=true, but we need to verify cloudflare_secret_key is configured + // If secret key is not configured, treat captcha as disabled to avoid blocking login + secretKey, err := h.repo.GetConfigByName("cloudflare_secret_key") + if err != nil { + return false, err + } + if secretKey == nil || strings.TrimSpace(secretKey.Value) == "" { + return false, nil + } + + return true, nil } func (h *Handler) markCaptchaToken(token string) {