Using Cloudflare Turnstile on a Astro form
Here’s how I used Cloudflare Turnstile on a Astro form to prevent spam and form submission abuse.
Set Turnstile up in the Cloudflare panel first, and grab the TURNSTILE_SITE_KEY and TURNSTILE_SITE_SECRET variables, put them in .env or anywhere you manage env vars.
Then in the Astro component:
<script
is:inline
src='https://challenges.cloudflare.com/turnstile/v0/api.js'
defer
async></script>
<form method='post'>
...
<div
class='cf-turnstile'
data-sitekey={import.meta.env
.TURNSTILE_SITE_KEY ||
process.env.TURNSTILE_SITE_KEY}>
</div>
<input
type='submit'
value='Login'
/>
</form>
On the server endpoint (might be same page, or not):
export async function processTurnstile(
cf_turnstile_response: string
) {
const url =
'https://challenges.cloudflare.com/turnstile/v0/siteverify'
const requestBody = new URLSearchParams({
secret:
import.meta.env.TURNSTILE_SITE_SECRET ||
process.env.TURNSTILE_SITE_SECRET,
response: cf_turnstile_response
})
const response = await fetch(url, {
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded'
},
body: requestBody.toString()
})
const data = await response.json()
return data.success
}
if (Astro.request.method === 'POST') {
const formData = await Astro.request.formData()
const email = formData.get('email')?.toString() || ''
const password =
formData.get('password')?.toString() || ''
const is_valid_turnstile = await processTurnstile(
formData.get('cf-turnstile-response')?.toString() || ''
)
if (!is_valid_turnstile) {
console.log('Invalid turnstile')
} else {
//valid, do something
}
} download all my books for free
- javascript handbook
- typescript handbook
- css handbook
- node.js handbook
- astro handbook
- html handbook
- next.js pages router handbook
- alpine.js handbook
- htmx handbook
- react handbook
- sql handbook
- git cheat sheet
- laravel handbook
- express handbook
- swift handbook
- go handbook
- php handbook
- python handbook
- cli handbook
- c handbook
subscribe to my newsletter to get them
Terms: by subscribing to the newsletter you agree the following terms and conditions and privacy policy. The aim of the newsletter is to keep you up to date about new tutorials, new book releases or courses organized by Flavio. If you wish to unsubscribe from the newsletter, you can click the unsubscribe link that's present at the bottom of each email, anytime. I will not communicate/spread/publish or otherwise give away your address. Your email address is the only personal information collected, and it's only collected for the primary purpose of keeping you informed through the newsletter. It's stored in a secure server based in the EU. You can contact Flavio by emailing flavio@flaviocopes.com. These terms and conditions are governed by the laws in force in Italy and you unconditionally submit to the jurisdiction of the courts of Italy.