Google reCAPTCHA
From AgileApps Support Wiki
What is reCAPTCHA?
reCAPTCHA protects the webforms from fraud and abuse without creating friction. It uses an advanced risk analysis engine and adaptive challenges to keep malicious software from engaging in abusive activities on the webforms. For more information, view the Google reCAPTCHA article.
How to enable reCAPTCHA in webforms?
Note: The following workflow applies to the OnPrem application. If keys are configured in LongJump and the Show Captcha is enabled for the web form, the captcha will be enabled by default. For new web forms, the captcha will be disabled and user can enable it based on their preference during the web form creation process.
Step 1: Generating Private and Public keys
- Go to the Google reCAPTCHA page.
- Click the v3 Admin Console button at the top.
- Enter a label for easy site identification (e.g., domain.com).
- Choose the desired reCAPTCHA type.
- In the Domains field, enter the desired domain (e.g., subdomain.domain.com) and click the + (Add domain) icon.
- If you have additional domains, add them in the next field.
- Read the terms and check the respective checkbox.
- Click the Submit button.
- The site key and secret key will now appear. The site key is the public key, and the secret key is the private key.
- Copy both keys. These keys need to be configured in LongJump.
Step 2: Configuring the public and private keys in LongJump
- Log in to your LongJump account.
- Navigate to Settings > Service Provider Settings > Service Configuration.
- Click the Edit button at the top.
- Under Basic Service Configuration, locate the Recaptcha Public Key and Recaptcha Private Key fields.
- Paste the site key copied from Google reCAPTCHA into the Recaptcha Public Key field.
- Paste the secret key copied from Google reCAPTCHA into the Recaptcha Private Key field.
- Click the Save button.
- Under Security Headers Configuration, you can observe that the CSP Whitelisted Domains and CORS Whitelisted Domains are populated automatically.