Bitzsoft.Integrations.Captcha.Aliyun 1.0.4

dotnet add package Bitzsoft.Integrations.Captcha.Aliyun --version 1.0.4
                    
NuGet\Install-Package Bitzsoft.Integrations.Captcha.Aliyun -Version 1.0.4
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Bitzsoft.Integrations.Captcha.Aliyun" Version="1.0.4" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Bitzsoft.Integrations.Captcha.Aliyun" Version="1.0.4" />
                    
Directory.Packages.props
<PackageReference Include="Bitzsoft.Integrations.Captcha.Aliyun" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Bitzsoft.Integrations.Captcha.Aliyun --version 1.0.4
                    
#r "nuget: Bitzsoft.Integrations.Captcha.Aliyun, 1.0.4"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Bitzsoft.Integrations.Captcha.Aliyun@1.0.4
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Bitzsoft.Integrations.Captcha.Aliyun&version=1.0.4
                    
Install as a Cake Addin
#tool nuget:?package=Bitzsoft.Integrations.Captcha.Aliyun&version=1.0.4
                    
Install as a Cake Tool

Bitzsoft.Integrations.Captcha.Aliyun

阿里云验证码 2.0 实现包 -- 前端 Captcha.js 自渲染 + 服务端 VerifyIntelligentCaptcha 二次校验。

功能特性

  • 无感验证:前端 SDK 自渲染,用户无感验证通过后回传 VerifyToken
  • 服务端二次校验:后端调阿里云 VerifyIntelligentCaptcha 接口验证 token 真伪与风险等级
  • POP RPC v1 签名:内置 HMAC-SHA1 签名(RFC 3986 URL 编码),无需引入阿里云 SDK
  • 零厂商 SDK 依赖:裸 HttpClient 直调 REST API,包体积小
  • 请求审计:内置 RequestLogging 管道,记录出站请求
  • fail-closed:响应异常或缺字段时一律判失败,绝不静默放行

安装

dotnet add package Bitzsoft.Integrations.Captcha.Aliyun
<PackageReference Include="Bitzsoft.Integrations.Captcha.Aliyun" Version="1.0.0" />

配置

appsettings.json

{
  "Captcha": {
    "Aliyun": {
      "AccessKeyId": "your-access-key-id",
      "AccessKeySecret": "your-access-key-secret",
      "SceneId": "your-scene-id",
      "AppKey": "your-app-key",
      "Region": "cn-hangzhou",
      "Endpoint": "captcha.cn-hangzhou.aliyuncs.com"
    }
  }
}
配置项 说明 必填 默认值
AccessKeyId 阿里云 AccessKey ID 是 -
AccessKeySecret 阿里云 AccessKey Secret(签名用,须脱敏) 是 -
SceneId 验证码场景 ID(控制台创建场景获得) 是 -
AppKey 验证码应用 AppKey(前端 SDK 初始化) 是 -
Region 地域 否 cn-hangzhou
Endpoint 服务端点 否 captcha.cn-hangzhou.aliyuncs.com
ScriptUrl 前端 SDK 脚本地址 否 阿里云 CDN
Timeout HTTP 超时 否 30s
HttpClientName 命名 HttpClient 标识 否 AliyunCaptchaProvider

注册服务

从 IConfiguration 绑定(推荐)

using Microsoft.Extensions.DependencyInjection;

builder.Services.AddBitzsoftAliyunCaptcha(
    builder.Configuration.GetSection("Captcha:Aliyun"));

委托配置

builder.Services.AddBitzsoftAliyunCaptcha(options =>
{
    options.AccessKeyId = "your-access-key-id";
    options.AccessKeySecret = "your-access-key-secret";
    options.SceneId = "your-scene-id";
    options.AppKey = "your-app-key";
});

注册后 ICaptchaProvider 与 ICaptchaProviderFactory 均可用(单厂商包也注册工厂)。

使用示例

生成前端 SDK 凭证

public class CaptchaController(ICaptchaProviderFactory factory) : ControllerBase
{
    [HttpGet("captcha/challenge")]
    public IActionResult Challenge()
    {
        var provider = factory.GetProvider(CaptchaProviderCode.Aliyun);
        var result = provider.GenerateAsync(new CaptchaGenerateRequest
        {
            Type = CaptchaType.Intelligent,
            Scene = "login"
        }).GetAwaiter().GetResult();

        // 将 AppKey / SceneId / ScriptUrl 返回给前端 SDK 初始化
        return Ok(result.Data);
    }
}

前端加载 AliyunCaptcha.js,用返回的 AppKey + SceneId 初始化,完成无感验证后拿到 VerifyToken。

服务端校验 token

[HttpPost("captcha/verify")]
public async Task<IActionResult> Verify([FromBody] VerifyDto dto)
{
    var provider = factory.GetProvider(CaptchaProviderCode.Aliyun);
    var result = await provider.VerifyAsync(new CaptchaVerifyRequest
    {
        Token = dto.VerifyToken,      // 前端回传
        RemoteIp = HttpContext.Connection.RemoteIpAddress?.ToString()
    });

    if (result.IsSuccess && result.Data!.Passed)
        return Ok();                  // 校验通过

    return BadRequest(result.ErrorMessage);  // 失败(含风险等级)
}

错误码

VerifyCode 反映风险等级:100 通过 / 100~900 风险递增 / 900 风险最高。校验失败时 ErrorCode 形如 VERIFY_900。

请求审计

内置 Bitzsoft.Integrations.RequestLogging 出站请求记录。持久化须宿主注册 IRequestLogStore:

services.AddRequestLogging<MyRequestLogStore>(opts =>
{
    opts.SensitiveFields.Add("AccessKeySecret");   // 确保密钥脱敏
});
services.AddBitzsoftAliyunCaptcha(builder.Configuration.GetSection("Captcha:Aliyun"));

安全说明

  • AccessKeySecret:通过环境变量 / Secret Manager 注入,禁止硬编码;务必加入 RequestLogging 脱敏字段
  • fail-closed:阿里云响应缺 VerifyResult 字段时一律判失败
  • token 一次性:VerifyToken 校验后即失效

依赖

包 说明
Bitzsoft.Integrations.Captcha 抽象层(接口 / 模型)
Bitzsoft.Integrations.Compatibility 基础工具库
Bitzsoft.Integrations.RequestLogging 出站请求审计
Microsoft.Extensions.Http IHttpClientFactory
Microsoft.Extensions.Options.ConfigurationExtensions Options 配置绑定
Microsoft.Extensions.Logging.Abstractions 日志抽象

相关包

Product Compatible and additional computed target framework versions.
.NET net5.0 is compatible.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Bitzsoft.Integrations.Captcha.Aliyun:

Package Downloads
Bitzsoft.Integrations.Captcha.All

验证码聚合包 — 包含阿里云 / 腾讯天御 / 极验 GeeTest 全部实现

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.4 119 9/23/2026
1.0.3 120 9/22/2026
1.0.2 132 8/29/2026
1.0.1 160 8/3/2026
1.0.0 150 8/2/2026
1.0.0-alpha.10 74 7/26/2026