Skip to content

Conversation

@joyceqin-stripe
Copy link
Collaborator

@joyceqin-stripe joyceqin-stripe commented Nov 24, 2025

Summary

The captcha token can expire. On the back end, its max_age is set to 1800 seconds, or 30 minutes. We treat the token as expired at 29 minutes to prevent the case where a user confirms at, say, 1799 seconds, and the back end sees a token that has just expired. After expiration, when the user confirms, we fetch a new token.

Motivation

HCaptcha project

Testing

Added test

Changelog

N/A

@joyceqin-stripe joyceqin-stripe marked this pull request as ready for review December 23, 2025 18:06
@joyceqin-stripe joyceqin-stripe requested review from a team as code owners December 23, 2025 18:06
Copy link
Collaborator

@wooj-stripe wooj-stripe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall

func fetchTokensWithTimeout() async -> ChallengeTokens {
let startTime = Date()
let isReady = await passiveCaptchaChallenge?.hasFetchedToken ?? false
let isReady = await passiveCaptchaChallenge?.isTokenReady ?? false
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IsTokenReady seems to be used for analytics, and we are changing the underlying definition of it -- I'm guessing we're prepared to update any dashboards/queries to filter out older clients with the older definition?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HCaptcha on MPE is not public yet, so this isn't affecting anything.

@joyceqin-stripe joyceqin-stripe merged commit a625eff into master Jan 9, 2026
8 checks passed
@joyceqin-stripe joyceqin-stripe deleted the joyceqin/captcha-token-retry branch January 9, 2026 19:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants