Skip to content

Conversation

@pontflorian
Copy link
Contributor

PR to fix #470.

According to #470, when verifying the reCAPTCHA token with verify_recaptcha, the HTTP request sent to Google's endpoint does not include a Referer header. Google rejects the request with a 403 Permission Denied error because the request lacks the expected referer/origin information.

This PR adds a Referer header during api_verification_enterprise method with a default value of Rails.application.default_url_options[:host].

Any improvement is welcome !

Pre-Merge Checklist

  • CHANGELOG.md updated with short summary for user facing changes

Copy link
Collaborator

@grosser grosser left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks reasonable and safe 👍

@grosser grosser merged commit 855f62d into ambethia:master Sep 14, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Empty referer header recaptcha enterprise leads to 403 Permission Denied

2 participants