Bitzsoft.Integrations.Captcha.Tencent 1.0.4

dotnet add package Bitzsoft.Integrations.Captcha.Tencent --version 1.0.4
                    
NuGet\Install-Package Bitzsoft.Integrations.Captcha.Tencent -Version 1.0.4
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Bitzsoft.Integrations.Captcha.Tencent" Version="1.0.4" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Bitzsoft.Integrations.Captcha.Tencent" Version="1.0.4" />
                    
Directory.Packages.props
<PackageReference Include="Bitzsoft.Integrations.Captcha.Tencent" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Bitzsoft.Integrations.Captcha.Tencent --version 1.0.4
                    
#r "nuget: Bitzsoft.Integrations.Captcha.Tencent, 1.0.4"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Bitzsoft.Integrations.Captcha.Tencent@1.0.4
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Bitzsoft.Integrations.Captcha.Tencent&version=1.0.4
                    
Install as a Cake Addin
#tool nuget:?package=Bitzsoft.Integrations.Captcha.Tencent&version=1.0.4
                    
Install as a Cake Tool

Bitzsoft.Integrations.Captcha.Tencent

腾讯天御验证码实现包 -- 前端 TCaptcha 自渲染 + 服务端 DescribeCaptchaResult 二次校验。

功能特性

  • 无感验证:前端 TCaptcha SDK 自渲染,验证通过后回传 ticket + Randstr
  • 服务端二次校验:后端调腾讯 DescribeCaptchaResult 接口验证 ticket 真伪
  • TC3-HMAC-SHA256 签名:内置腾讯云 API v3 签名(HMAC 密钥派生链),无需引入腾讯云 SDK
  • 签名健壮:Content-Type 签名值从实际请求内容读取,保证签名值与发送值完全一致
  • 零厂商 SDK 依赖:裸 HttpClient 直调 REST API
  • 请求审计:内置 RequestLogging 管道

安装

dotnet add package Bitzsoft.Integrations.Captcha.Tencent
<PackageReference Include="Bitzsoft.Integrations.Captcha.Tencent" Version="1.0.0" />

配置

appsettings.json

{
  "Captcha": {
    "Tencent": {
      "SecretId": "your-tencent-secret-id",
      "SecretKey": "your-tencent-secret-key",
      "CaptchaAppId": 1234567,
      "AppSecretKey": "your-captcha-app-secret-key",
      "Region": "ap-guangzhou",
      "Endpoint": "captcha.tencentcloudapi.com"
    }
  }
}
配置项 说明 必填 默认值
SecretId 腾讯云 SecretId 是 -
SecretKey 腾讯云 SecretKey(TC3 签名用,须脱敏) 是 -
CaptchaAppId 验证码应用 CaptchaAppId(前端 + 后端均用) 是 -
AppSecretKey 验证码应用 AppSecretKey(随请求体传输,须脱敏) 是 -
Region 地域 否 ap-guangzhou
Endpoint 服务端点 否 captcha.tencentcloudapi.com
ScriptUrl 前端 SDK 脚本地址 否 腾讯 CDN
Timeout HTTP 超时 否 30s
HttpClientName 命名 HttpClient 标识 否 TencentCaptchaProvider

安全提示:腾讯 DescribeCaptchaResult 接口要求 AppSecretKey 作为业务参数明文随请求体传输(系腾讯既定设计,非连接器可改)。务必将该字段加入 RequestLogging 脱敏配置。

注册服务

从 IConfiguration 绑定(推荐)

using Microsoft.Extensions.DependencyInjection;

builder.Services.AddBitzsoftTencentCaptcha(
    builder.Configuration.GetSection("Captcha:Tencent"));

委托配置

builder.Services.AddBitzsoftTencentCaptcha(options =>
{
    options.SecretId = "your-tencent-secret-id";
    options.SecretKey = "your-tencent-secret-key";
    options.CaptchaAppId = 1234567;
    options.AppSecretKey = "your-captcha-app-secret-key";
});

使用示例

生成前端 SDK 凭证

var provider = factory.GetProvider(CaptchaProviderCode.Tencent);
var result = await provider.GenerateAsync(new CaptchaGenerateRequest { Type = CaptchaType.Intelligent });
// result.Data.AppId → CaptchaAppId,前端 TCaptcha 初始化用

前端加载 TCaptcha.js,用 CaptchaAppId 初始化,验证通过后拿到 ticket + Randstr。

服务端校验 ticket

[HttpPost("captcha/verify")]
public async Task<IActionResult> Verify([FromBody] VerifyDto dto)
{
    var provider = factory.GetProvider(CaptchaProviderCode.Tencent);
    var result = await provider.VerifyAsync(new CaptchaVerifyRequest
    {
        Token = dto.Ticket,       // 前端回传的 ticket
        Randstr = dto.Randstr,    // 前端回传的随机串
        RemoteIp = HttpContext.Connection.RemoteIpAddress?.ToString()
    });

    if (result.IsSuccess && result.Data!.Passed)
        return Ok();

    return BadRequest(result.ErrorMessage);
}

错误码

CaptchaCode:0 校验通过,非 0 失败。接口级错误(鉴权失败等)从 Error.Code 透传为 ErrorCode。

请求审计

services.AddRequestLogging<MyRequestLogStore>(opts =>
{
    opts.SensitiveFields.Add("AppSecretKey");   // 关键:腾讯 AppSecretKey 随请求体传输
    opts.SensitiveFields.Add("SecretKey");
});
services.AddBitzsoftTencentCaptcha(builder.Configuration.GetSection("Captcha:Tencent"));

安全说明

  • SecretKey / AppSecretKey:通过环境变量注入,禁止硬编码;务必加入 RequestLogging 脱敏字段
  • AppSecretKey 传输:随每个校验请求体明文传输,是腾讯接口的既定要求,务必脱敏
  • ticket 一次性:校验后即失效

依赖

包 说明
Bitzsoft.Integrations.Captcha 抽象层(接口 / 模型)
Bitzsoft.Integrations.Compatibility 基础工具库
Bitzsoft.Integrations.RequestLogging 出站请求审计
Microsoft.Extensions.Http IHttpClientFactory
Microsoft.Extensions.Options.ConfigurationExtensions Options 配置绑定
Microsoft.Extensions.Logging.Abstractions 日志抽象

相关包

Product Compatible and additional computed target framework versions.
.NET net5.0 is compatible.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Bitzsoft.Integrations.Captcha.Tencent:

Package Downloads
Bitzsoft.Integrations.Captcha.All

验证码聚合包 — 包含阿里云 / 腾讯天御 / 极验 GeeTest 全部实现

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.4 134 9/23/2026
1.0.2 131 8/29/2026
1.0.1 149 8/3/2026
1.0.0 148 8/2/2026
1.0.0-alpha.10 72 7/26/2026