cwp edge captcha
shipped 2.0.0cwp edge captcha [env] [flags]
Acts on the local site. Name an environment to act there instead.
| Argument | What it is | Default |
|---|---|---|
[env] | environment to provision (default: default_environment in cwp.yml) |
| Flag | What it does | Default |
|---|---|---|
--force | override the protected-environment refusal | off |
--no-backup | skip the remote backup taken before the write | on |
--yes | skip the confirmation prompt | off |
--with-agent | with —dry-run on a host with no shell: install and remove the PHP agent so the plan is real | off |
Plus the shared flags --json, -v, --verbose, -q, --quiet and --dry-run.
What it does
edge captcha provisions the edge’s captcha and writes its keys into the
builder (F-137). cwp finds or creates the Turnstile widget for the site’s
domains at the edge. It reads the widget’s site key and secret and writes both
into the builder’s form settings. The secret flows from the edge’s API to the
site and never touches the tree.
$ cwp edge captcha dev
✓ remote backup — …
? Provision turnstile for dev and write the keys into the builder?
✓ edge captcha (dev) — turnstile created
It is an upward write. So it takes the guards every upward write takes: the
protected-environment refusal (--force), a remote backup first
(--no-backup), and a confirmation. It provisions a slot only when the edge
issues that captcha. The builder must also hold no key, or hold one that no
widget of the zone answers.
Creating a widget needs the edge token to carry Turnstile:Edit. A token without it refuses with that instruction. Enabling the captcha on a particular form is editorial in the builder and travels with the content.
What it does not do
- It does not put the secret in the tree. Both keys stay
credential(F-130); cwp only ever reads back the site key, and that one is public. - It does not enable the captcha per form. That is a form setting in the builder.
- It does not provision a captcha the edge does not issue. It leaves a reCAPTCHA slot in the builder alone.
- It does not run on
local. The local site names no edge; everycwp db pullwrites the vendor’s sandbox pair there, andcwp doctorwarns when that pair turns up on an environment.