SetCaptchaServer was .so-era injection — nothing wasm-side ever called it, so the verifier was permanently nil and captcha-enabled booking blocks failed closed on every submission. A guest can't hold the host's stateful captcha server; the host now verifies+consumes the cap-token before dispatch and stamps the unforgeable X-Bn-Verified-Captcha trusted header (pluginsdk v0.2.2 auth.CaptchaVerified). Fail-closed semantics preserved: no stamp = reject. Deletes the last block/core import (captcha) and the test-side PoW solver; go.mod no longer requires core. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
23 lines
645 B
Modula-2
23 lines
645 B
Modula-2
module git.dev.alexdunmow.com/block/calcomblock
|
|
|
|
go 1.26.4
|
|
|
|
require (
|
|
git.dev.alexdunmow.com/block/pluginsdk v0.2.2
|
|
github.com/a-h/templ v0.3.1020
|
|
github.com/go-chi/chi/v5 v5.3.0
|
|
github.com/google/uuid v1.6.0
|
|
github.com/jackc/pgx/v5 v5.10.0
|
|
github.com/nyaruka/phonenumbers v1.8.0
|
|
)
|
|
|
|
require (
|
|
connectrpc.com/connect v1.20.0 // indirect
|
|
github.com/BurntSushi/toml v1.6.0 // indirect
|
|
github.com/jackc/pgpassfile v1.0.0 // indirect
|
|
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
|
|
golang.org/x/mod v0.37.0 // indirect
|
|
golang.org/x/text v0.36.0 // indirect
|
|
google.golang.org/protobuf v1.36.11 // indirect
|
|
)
|