A widget fix. Browser-side only — no server change, no API change.
Fixed
A form left open past the challenge lifetime can be solved again.
The widget fetches a proof-of-work challenge when it loads, and the server holds that challenge for five minutes. The widget never replaced it, so a form filled in slowly — or a tab returned to later — submitted a solution to a challenge the server no longer had. The server refused the proof and withheld the token, and the checkbox reported "Verification failed" to a visitor who had done nothing wrong.
The failure path also left the spent challenge in place, so clicking again repeated the same refusal until the page was reloaded.
The widget now replaces a challenge at or inside a 15-second margin of its expiry before solving, and fetches a fresh one after a failed attempt so the retry has something to work with.
Affected: every release up to and including 1.34.0, self-hosted and CDN alike.
Upgrading
Nothing to change. Self-hosted servers pick this up when you deploy the new widget. If you load the widget from the CDN, bump the pinned version and the integrity digest.
Subresource Integrity
fcaptcha.js sha384-4ref7/zOui4hlOnUy1OJYq8TsgjATG2SQ64Ub3lTF5ur5sKyILGpgyjaDHBh2KVL
dist/fcaptcha.min.js sha384-s1fNbu01k4a6Vq5tfGv57pFU4pHjxoyjYvFGYr8xiB2CYRpDo7wATcM2T7DldGeP