HeCAPTe: a stateless, privacy-first CAPTCHA service you can embed almost anywhere.
-
Hello @themeerkat
With Cloudron 9.1 we have added community app support.
Please check the latest documentation for package publishing https://docs.cloudron.io/packaging/publishing
Could you update your repo to include these changes? -
Hello @themeerkat
With Cloudron 9.1 we have added community app support.
Please check the latest documentation for package publishing https://docs.cloudron.io/packaging/publishing
Could you update your repo to include these changes?Hello @themeerkat
With Cloudron 9.1 we have added community app support.
Please check the latest documentation for package publishing https://docs.cloudron.io/packaging/publishing
Could you update your repo to include these changes?Done. Also, the issue with the previous version is now resolved!
To install it as a community app, use this link:
https://codeberg.org/TheMeerkat/HeCAPTe-Cloudron/raw/branch/main/CloudronVersions.json -
Hello @themeerkat
I have added your package to the list: https://forum.cloudron.io/topic/15172/community-apps -
Massive 2.0 update. Following SemVar, that means a breaking change, and... yeah, it's breaking all right!
I've consolidated the two repositories and made several improvements that did, unfortunately, invalidate existing installs; I figured it was best to do this now, while everything is still early. It does mean that updates of the old app are no longer possible, however. You will need to reinstall from scratch as a new community app with
https://codeberg.org/TheMeerkat/HeCAPTe/raw/branch/main/CloudronVersions.jsonas the source file.Sorry about this. It allowed for me to implement the requested aliasing, plus made it much easier for me to localize it (per a Codeberg issue) in the future. I won't have to do that again.
@james Could you update the link to the versions file in the masterlist, please?
-
Hello @themeerkat
I have updated both URLs and made you an editor for the detailed post https://forum.cloudron.io/post/121505
Now you can edit this one freely. -
Massive 2.0 update. Following SemVar, that means a breaking change, and... yeah, it's breaking all right!
I've consolidated the two repositories and made several improvements that did, unfortunately, invalidate existing installs; I figured it was best to do this now, while everything is still early. It does mean that updates of the old app are no longer possible, however. You will need to reinstall from scratch as a new community app with
https://codeberg.org/TheMeerkat/HeCAPTe/raw/branch/main/CloudronVersions.jsonas the source file.Sorry about this. It allowed for me to implement the requested aliasing, plus made it much easier for me to localize it (per a Codeberg issue) in the future. I won't have to do that again.
@james Could you update the link to the versions file in the masterlist, please?
@TheMeerkat Woohoo! It works like a charm. Thank you so much for your work.
-
The significantly improved v3.0.0 is out now!
[3.0.0]
- Moved the project home to https://tangled.org/katsuricata.com/HeCAPTe (from Codeberg) and the container image to Docker Hub (
docker.io/katsuricata/hecapte). - Fixed browser-flow regressions that shipped in 2.0.0: the first-run setup page never loaded
wasm_exec.js(sonew Go()threw and setup could never complete through the UI), and the password page calledbufferDecode/bufferEncodewithout loadingadmin.js. Added a template test that fails when a page usesnew Go(),solveChallenge(), orbufferDecode/bufferEncodewithout loading the script that defines it. - Added an Equihash difficulty floor (
crypto.MinN = 60).ValidateParams,tokens.GenerateChallenge, andVerifySolutionall reject parameters below the floor, so no configuration path can turn the verifier into a free token oracle. The server warns loudly when the global preset or a site override useslow, and flags weak sites on the admin dashboard. - Added per-IP rate limiting (token bucket) on the unauthenticated admin endpoints: 10 req/min (burst 5) on the login/setup challenge fetches and 5 req/min (burst 2) on the login POST. Buckets key on the peer address and honor
X-Forwarded-Foronly behindTRUST_PROXY=1. - Added security response headers:
X-Content-Type-Options: nosniff,frame-ancestors 'none',X-Frame-Options: DENY, andReferrer-Policy: same-origin. - Added a one-time startup warning when
X-Forwarded-Protoarrives butTRUST_PROXYis unset, turning a silent reverse-proxy misconfiguration into an observable one. - Upgraded
modernc.org/sqlitefrom 1.55.0 to 1.56.0 (bundled SQLite C library; staying current is the only CVE mitigation). - Expired WebAuthn reauthentication tokens are now swept on each store, so the map cannot grow without bound.
- Updated the README (difficulty floor, rate limiting, response headers, forwarded-header warning, project layout) and added/refreshed tests for every change.
- Moved the project home to https://tangled.org/katsuricata.com/HeCAPTe (from Codeberg) and the container image to Docker Hub (
-
As a result of the first entry, the CloudronVersions.json link has changed:
https://mirror.tangled.network/xrpc/sh.tangled.git.temp.getBlob?path=CloudronVersions.json&ref=main&repo=did%3Aplc%3Apomgtubhgnuew7wmpwgk7dzdI'll manually update the Codeberg one for a while, but you should change it at some point.
-
Hello @themeerkat
Maybe you want to add your app to the community app store?
https://ca.cloudron.io/ -
Hello @themeerkat
Maybe you want to add your app to the community app store?
https://ca.cloudron.io/@james had no idea that was a thing! thanks for the tip

Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login