Create the concept of API keys to allow third party clients to skip the CAPTCHA check on spot submission

This commit is contained in:
Ian Renton
2026-09-27 16:12:48 +01:00
parent d79c89c74a
commit 5d8cd38351
14 changed files with 155 additions and 42 deletions
+14 -6
View File
@@ -354,13 +354,21 @@ allow_spotting: true
# this, and will log in using the spotter's callsign to send the spot. Upstream spotting to POTA, SOTA etc. is a work
# in progress. Requires allow_spotting to also be true. Set to false to only accept spots into the local Spothole
# database, without forwarding them to any external service.
allow_upstream_spotting: false
allow_upstream_spotting: true
# Google reCAPTCHA v2 keys for CAPTCHA protection on upstream spot submission. Both keys must be set to enable CAPTCHA.
# Leave both empty to disable CAPTCHA (e.g. for a private/trusted server) or if allow_spotting is false, in which case
# they will do nothing. Note that with CAPTCHA enabled, this will prevent third-party clients submitting spots through
# Spothole unless the clients are web-based, use the same site key, have their domains enabled in your reCAPTCHA config,
# and of course their user solves the CAPTCHA.
# Require a CAPTCHA or API key to submit spots? If false, anyone can submit spots via the web interface or the API. If
# true, users of the web interface must solve a CAPTCHA (see reCAPTCHA config below), and third-party clients must
# provide one of the API keys listed below. Recommended for public servers where spotting is allowed.
protect_spot_submission: true
# API keys used by third-party client developers. Clients provide a key in the "X-API-Key" request header when calling
# the add spot API, and this is compared against the server's list below. Generate a long random string for each
# client you want to allow (e.g. openssl rand -hex 32), and send it to them privately. To revoke a client's access,
# remove their key from this list and restart Spothole.
api_keys: []
# Google reCAPTCHA v2 keys for CAPTCHA protection on spot submission from the web UI. Both keys must be set to enable
# CAPTCHA. They are only used if protect_spot_submission is true.
# You can sign up for reCAPTCHA at https://www.google.com/recaptcha/
recaptcha_site_key: ""
recaptcha_secret_key: ""