Skip to content

cwp edge captcha

shipped 2.0.0
cwp edge captcha [env] [flags]

Acts on the local site. Name an environment to act there instead.

tree → site

ArgumentWhat it isDefault
[env]environment to provision (default: default_environment in cwp.yml)
FlagWhat it doesDefault
--forceoverride the protected-environment refusaloff
--no-backupskip the remote backup taken before the writeon
--yesskip the confirmation promptoff
--with-agentwith —dry-run on a host with no shell: install and remove the PHP agent so the plan is realoff

Plus the shared flags --json, -v, --verbose, -q, --quiet and --dry-run.

What it does

edge captcha provisions the edge’s captcha and writes its keys into the builder (F-137). cwp finds or creates the Turnstile widget for the site’s domains at the edge. It reads the widget’s site key and secret and writes both into the builder’s form settings. The secret flows from the edge’s API to the site and never touches the tree.

$ cwp edge captcha dev
✓ remote backup — …
? Provision turnstile for dev and write the keys into the builder?
✓ edge captcha (dev) — turnstile created

It is an upward write. So it takes the guards every upward write takes: the protected-environment refusal (--force), a remote backup first (--no-backup), and a confirmation. It provisions a slot only when the edge issues that captcha. The builder must also hold no key, or hold one that no widget of the zone answers.

Creating a widget needs the edge token to carry Turnstile:Edit. A token without it refuses with that instruction. Enabling the captcha on a particular form is editorial in the builder and travels with the content.

What it does not do

  • It does not put the secret in the tree. Both keys stay credential (F-130); cwp only ever reads back the site key, and that one is public.
  • It does not enable the captcha per form. That is a form setting in the builder.
  • It does not provision a captcha the edge does not issue. It leaves a reCAPTCHA slot in the builder alone.
  • It does not run on local. The local site names no edge; every cwp db pull writes the vendor’s sandbox pair there, and cwp doctor warns when that pair turns up on an environment.