fix: make image captcha work with csp (#39555)

fix #39553
This commit is contained in:
wxiaoguang
2026-10-03 07:40:13 +00:00
committed by GitHub
parent 1f615a406f
commit f24f3e1eda
2 changed files with 14 additions and 1 deletions
+1 -1
View File
@@ -1,5 +1,5 @@
{{if .EnableCaptcha}}{{if eq .CaptchaType "image"}}
<div class="inline field tw-text-center">
<div class="inline field tw-text-center" data-global-init="initImageCaptcha">
{{.Captcha.CreateHTML}}
</div>
<div class="required field {{if .Err_Captcha}}error{{end}}">
+13
View File
@@ -1,6 +1,19 @@
import {isDarkTheme} from '../utils.ts';
import {registerGlobalInitFunc} from '../modules/observer.ts';
export async function initCaptcha() {
registerGlobalInitFunc('initImageCaptcha', (el: HTMLElement) => {
const a = el.querySelector('a')!;
a.removeAttribute('href'); // remove generated href="javascript:"
const img = el.querySelector('img')!;
img.removeAttribute('onclick'); // remove generated onclick="...." and use our own event listener
img.addEventListener('click', () => {
const url = new URL(img.src);
url.searchParams.set('reload', String(Date.now()));
img.src = url.href;
});
});
const captchaEl = document.querySelector('#captcha');
if (!captchaEl) return;