5.9.0
API
API v5.9.0 — Proof of work & captcha challenge.
- Added endpoint GET /pow: a proof of work replacing the captcha — the server issues a
saltand a difficulty, the client looks for anoncewhosesha256fingerprint starts with that many zeros, then posts it back for verification. At the default difficulty of4, solving takes under a second in a browser and stays imperceptible to a person, but becomes ruinous for a bot repeating it thousands of times. It is the only anti-bot protection a vision model cannot shortcut, and the documentation now recommends preferring it over the visual captcha. - GET /captcha gains a
challengemode: the image comes with a signed token in theX-Captcha-Tokenheader, and the answer is no longer delivered in clear. It exists only inside the token's signature — impossible to extract, even by intercepting the response. APOST /captchacarryingtokenandanswerthen returns{ "valid": true }. - The rendering of that
challengemode is hardened against automated reading: glyphs overlap so they cannot be segmented, ride a sine baseline, mix font families, and are crossed by strokes drawn in the text's own colors, which no filter can remove. The default mode does not change by a single pixel. - Captcha and proof-of-work tokens are single-use and expire after
5minutes: a replayed token answersused, an expired oneexpired, a forged one or one from another instancewrong. - The
CHALLENGE_SECRETvariable signs those tokens. Until it is set, each process invents its own key: tokens stop being valid after a restart and are rejected by neighbouring instances — to be defined for any deployment running more than one process. - The
X-Captcha-TextandX-Captcha-Tokenheaders are now exposed to browser JavaScript; until now they stayed invisible from a web page, for lack of a CORS declaration. - Logs now distinguish severity levels: a server error is recorded as
error, a client refusal aswarn, and the rest asinfo.
Documentation
- Added the documentation pages for Pow, covering the challenge and a browser solving example, and Pow verification for checking a solved challenge.
- Rewrote Captcha for the two modes, with a callout recommending Pow for anti-bot protection, and added Captcha verification for the
POSTroute. - Both endpoints now expose one page per HTTP method, grouped in the sidebar like Chat and Tic-Tac-Toe.
- Corrected stale values on the Captcha page inherited from v4: the
widthdefault is 60 × the text length rather than300,heightis120rather than150,noiseis a level (low,medium,high) rather than a number of lines, and theNoise must be one of…error starts with a capital letter. - Added the endpoint to the sidebar, the Playground registry and the homepage feature cards.