Skip to content

v1.37.0

Choose a tag to compare

@cport1 cport1 released this 11 Sep 00:34
· 21 commits to main since this release

Two detection changes on all three servers, plus a widget update that supports one of them. Deploy the server and the widget together.

Changed

Tokens are rate-limited per device. After 10 verifications in a minute from one page instance on one device at one address, the token is withheld with reason: rate_limited. The per-address rate detection stays as it was. The gate keys on the widget instance as well as address and fingerprint, so identical machines behind one address do not share a budget.

The keyboard-only exemption checks key holds. The accessibility exemption for visitors who use no pointer now asks, when hold data is present, that key holds look like fingers. A client that releases keys within a few milliseconds no longer passes as a keyboard user. A visitor with no hold data, including one on an older widget or one who only tabs to the checkbox, keeps the exemption. The widget now reports an average key hold alongside its key count; durations only, never which key.

Measured on the benchmark corpus: human false-positive rate 0.00% across 126 samples, agent catch rate unchanged, false-positive gate passes.

Affected: every release up to and including 1.36.0.

Upgrading

Deploy the server and the widget. Integrators reading the reason field will see a new value, rate_limited, documented in the README. If you load the widget from the CDN, bump the pinned version and the integrity digest.

Subresource Integrity

fcaptcha.js           sha384-3mu0z7MFPsll3bGhUl8FJ29m3Y3MwcQcdpsO27PRVdTEcD/4FbXBXbZJSGl2S20h
dist/fcaptcha.min.js  sha384-JUw4SWPKyPVEiJDQTIhcMhtV/I4x22ouw1FJuezjioboYERR1BiPVtyjxW4ROeMA