feat: add captcha validation to career portal applications - #785
Merged
anonymoususer72041 merged 5 commits intoJul 8, 2026
Merged
Conversation
anonymoususer72041
force-pushed
the
feature/careers-portal-captcha
branch
from
May 14, 2026 09:55
235ec68 to
3e69c43
Compare
anonymoususer72041
force-pushed
the
feature/careers-portal-captcha
branch
from
July 8, 2026 14:07
3e69c43 to
9cf97f6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR adds captcha support to the career portal application flow. It introduces the
gregwar/captchadependency, serves captcha images through the career portal module, renders captcha fields in career portal templates and validates submitted captcha phrases before accepting career portal applications.The default career portal template is updated to include a required captcha field for new installations and updated templates. The rendering logic supports both
<input-captcha>and<input-captcha req>, while the required variant is used to trigger server-side validation.Motivation
Public career portal application forms can be targeted by automated spam submissions. Adding captcha validation provides a lightweight protection mechanism for the default application form without changing the existing workflow for reviewing submitted candidates.
The implementation keeps the feature template-driven, so installations can control whether captcha validation is required through the career portal template content. This keeps the change close to the existing OpenCATS customization model while improving the default protection for public application forms.