Bitzsoft.Integrations.Captcha.Aliyun
1.0.4
dotnet add package Bitzsoft.Integrations.Captcha.Aliyun --version 1.0.4
NuGet\Install-Package Bitzsoft.Integrations.Captcha.Aliyun -Version 1.0.4
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Bitzsoft.Integrations.Captcha.Aliyun" Version="1.0.4" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Bitzsoft.Integrations.Captcha.Aliyun" Version="1.0.4" />
<PackageReference Include="Bitzsoft.Integrations.Captcha.Aliyun" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Bitzsoft.Integrations.Captcha.Aliyun --version 1.0.4
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Bitzsoft.Integrations.Captcha.Aliyun, 1.0.4"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Bitzsoft.Integrations.Captcha.Aliyun@1.0.4
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Bitzsoft.Integrations.Captcha.Aliyun&version=1.0.4
#tool nuget:?package=Bitzsoft.Integrations.Captcha.Aliyun&version=1.0.4
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Bitzsoft.Integrations.Captcha.Aliyun
阿里云验证码 2.0 实现包 -- 前端 Captcha.js 自渲染 + 服务端 VerifyIntelligentCaptcha 二次校验。
功能特性
- 无感验证:前端 SDK 自渲染,用户无感验证通过后回传 VerifyToken
- 服务端二次校验:后端调阿里云
VerifyIntelligentCaptcha接口验证 token 真伪与风险等级 - POP RPC v1 签名:内置 HMAC-SHA1 签名(RFC 3986 URL 编码),无需引入阿里云 SDK
- 零厂商 SDK 依赖:裸 HttpClient 直调 REST API,包体积小
- 请求审计:内置 RequestLogging 管道,记录出站请求
- fail-closed:响应异常或缺字段时一律判失败,绝不静默放行
安装
dotnet add package Bitzsoft.Integrations.Captcha.Aliyun
<PackageReference Include="Bitzsoft.Integrations.Captcha.Aliyun" Version="1.0.0" />
配置
appsettings.json
{
"Captcha": {
"Aliyun": {
"AccessKeyId": "your-access-key-id",
"AccessKeySecret": "your-access-key-secret",
"SceneId": "your-scene-id",
"AppKey": "your-app-key",
"Region": "cn-hangzhou",
"Endpoint": "captcha.cn-hangzhou.aliyuncs.com"
}
}
}
| 配置项 | 说明 | 必填 | 默认值 |
|---|---|---|---|
AccessKeyId |
阿里云 AccessKey ID | 是 | - |
AccessKeySecret |
阿里云 AccessKey Secret(签名用,须脱敏) | 是 | - |
SceneId |
验证码场景 ID(控制台创建场景获得) | 是 | - |
AppKey |
验证码应用 AppKey(前端 SDK 初始化) | 是 | - |
Region |
地域 | 否 | cn-hangzhou |
Endpoint |
服务端点 | 否 | captcha.cn-hangzhou.aliyuncs.com |
ScriptUrl |
前端 SDK 脚本地址 | 否 | 阿里云 CDN |
Timeout |
HTTP 超时 | 否 | 30s |
HttpClientName |
命名 HttpClient 标识 | 否 | AliyunCaptchaProvider |
注册服务
从 IConfiguration 绑定(推荐)
using Microsoft.Extensions.DependencyInjection;
builder.Services.AddBitzsoftAliyunCaptcha(
builder.Configuration.GetSection("Captcha:Aliyun"));
委托配置
builder.Services.AddBitzsoftAliyunCaptcha(options =>
{
options.AccessKeyId = "your-access-key-id";
options.AccessKeySecret = "your-access-key-secret";
options.SceneId = "your-scene-id";
options.AppKey = "your-app-key";
});
注册后
ICaptchaProvider与ICaptchaProviderFactory均可用(单厂商包也注册工厂)。
使用示例
生成前端 SDK 凭证
public class CaptchaController(ICaptchaProviderFactory factory) : ControllerBase
{
[HttpGet("captcha/challenge")]
public IActionResult Challenge()
{
var provider = factory.GetProvider(CaptchaProviderCode.Aliyun);
var result = provider.GenerateAsync(new CaptchaGenerateRequest
{
Type = CaptchaType.Intelligent,
Scene = "login"
}).GetAwaiter().GetResult();
// 将 AppKey / SceneId / ScriptUrl 返回给前端 SDK 初始化
return Ok(result.Data);
}
}
前端加载 AliyunCaptcha.js,用返回的 AppKey + SceneId 初始化,完成无感验证后拿到 VerifyToken。
服务端校验 token
[HttpPost("captcha/verify")]
public async Task<IActionResult> Verify([FromBody] VerifyDto dto)
{
var provider = factory.GetProvider(CaptchaProviderCode.Aliyun);
var result = await provider.VerifyAsync(new CaptchaVerifyRequest
{
Token = dto.VerifyToken, // 前端回传
RemoteIp = HttpContext.Connection.RemoteIpAddress?.ToString()
});
if (result.IsSuccess && result.Data!.Passed)
return Ok(); // 校验通过
return BadRequest(result.ErrorMessage); // 失败(含风险等级)
}
错误码
VerifyCode 反映风险等级:100 通过 / 100~900 风险递增 / 900 风险最高。校验失败时 ErrorCode 形如 VERIFY_900。
请求审计
内置 Bitzsoft.Integrations.RequestLogging 出站请求记录。持久化须宿主注册 IRequestLogStore:
services.AddRequestLogging<MyRequestLogStore>(opts =>
{
opts.SensitiveFields.Add("AccessKeySecret"); // 确保密钥脱敏
});
services.AddBitzsoftAliyunCaptcha(builder.Configuration.GetSection("Captcha:Aliyun"));
安全说明
- AccessKeySecret:通过环境变量 / Secret Manager 注入,禁止硬编码;务必加入 RequestLogging 脱敏字段
- fail-closed:阿里云响应缺
VerifyResult字段时一律判失败 - token 一次性:VerifyToken 校验后即失效
依赖
| 包 | 说明 |
|---|---|
Bitzsoft.Integrations.Captcha |
抽象层(接口 / 模型) |
Bitzsoft.Integrations.Compatibility |
基础工具库 |
Bitzsoft.Integrations.RequestLogging |
出站请求审计 |
Microsoft.Extensions.Http |
IHttpClientFactory |
Microsoft.Extensions.Options.ConfigurationExtensions |
Options 配置绑定 |
Microsoft.Extensions.Logging.Abstractions |
日志抽象 |
相关包
- Bitzsoft.Integrations.Captcha -- 抽象层
- Bitzsoft.Integrations.Captcha.Tencent -- 腾讯天御实现
- Bitzsoft.Integrations.Captcha.Geetest -- 极验 GeeTest 实现
- Bitzsoft.Integrations.Captcha.All -- 聚合包
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 is compatible. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Bitzsoft.Integrations.Captcha (>= 1.0.4)
- Bitzsoft.Integrations.Compatibility (>= 1.0.4)
- Bitzsoft.Integrations.RequestLogging (>= 1.0.4)
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Http (>= 10.0.10)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Options.ConfigurationExtensions (>= 10.0.10)
-
net5.0
- Bitzsoft.Integrations.Captcha (>= 1.0.4)
- Bitzsoft.Integrations.Compatibility (>= 1.0.4)
- Bitzsoft.Integrations.RequestLogging (>= 1.0.4)
- Microsoft.Extensions.Configuration.Abstractions (>= 5.0.0)
- Microsoft.Extensions.Http (>= 5.0.0)
- Microsoft.Extensions.Logging.Abstractions (>= 5.0.0)
- Microsoft.Extensions.Options.ConfigurationExtensions (>= 5.0.0)
-
net8.0
- Bitzsoft.Integrations.Captcha (>= 1.0.4)
- Bitzsoft.Integrations.Compatibility (>= 1.0.4)
- Bitzsoft.Integrations.RequestLogging (>= 1.0.4)
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Http (>= 10.0.10)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Options.ConfigurationExtensions (>= 10.0.10)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Bitzsoft.Integrations.Captcha.Aliyun:
| Package | Downloads |
|---|---|
|
Bitzsoft.Integrations.Captcha.All
验证码聚合包 — 包含阿里云 / 腾讯天御 / 极验 GeeTest 全部实现 |
GitHub repositories
This package is not used by any popular GitHub repositories.