Pythoni integratsioon

Pythoni saab täielikult kaitsta — ilma paketi ja sõltuvusteta. Kontroll on üksainus HTTPS-päring.

Me ei avalda Pythoni SDK-d. See ütleb midagi meie levituse, mitte teie kaitse kohta: mida SDK-d teevad, teeb allolev päring standardteegiga.

1. Vidina lisamine

Skript mõõdab käitumist brauseris ja lisab igale vormile peidetud välja. Lisage see üks kord lehtede päisesse.

HTMLhtml
<!-- Add to <head> with SRI for security -->
(function () {
  var KEY = "YOUR_API_KEY";
  var SITE = location.hostname;
  var V = "2025.09.1";
  var s = document.createElement('script');
  s.src = "https://api.silentshield.io/client.js?k=" + encodeURIComponent(KEY)
    + "&v=" + encodeURIComponent(V)
    + "&site=" + encodeURIComponent(SITE);
  s.async = true;
  s.crossOrigin = "anonymous";
  document.head.appendChild(s);
})();

2. Kontroll serveris

Lugege saatmisel peidetud väli ja küsige meilt, enne kui esituse vastu võtate. Ilma selle sammuta otsustab ainult brauser — ja JavaScriptita robot läheb sellest mööda.

Pythonpython
# No package required — the check is one HTTPS POST.
# Standard library only: nothing to install, nothing to keep updated.
import json
import os
import urllib.error
import urllib.request

VERIFY_URL = "https://api.silentshield.io/api/v1/captcha/verify-nonce"
API_KEY = os.environ["SILENTSHIELD_KEY"]  # never hard-code it


def is_human(nonce: str) -> bool:
    """Ask SilentShield about one submission.

    The hidden field `behavior_nonce` is injected by client.js;
    read it from the posted form and hand it over unchanged.
    """
    if not nonce:
        return False

    request = urllib.request.Request(
        VERIFY_URL,
        data=json.dumps({"nonce": nonce}).encode(),
        headers={
            "Content-Type": "application/json",
            "X-Api-Key": API_KEY,
            # Tells us which integration is in use, exactly like the SDKs do.
            "X-SS-SDK": "python-inline/1",
        },
        method="POST",
    )

    try:
        with urllib.request.urlopen(request, timeout=5) as response:
            data = json.loads(response.read())
    except (urllib.error.URLError, TimeoutError, ValueError):
        # We are unreachable. Let the visitor through: a real customer turned
        # away costs more than a bot let in. Flip this to False only if you
        # would rather lose submissions than accept one unchecked.
        return True

    return (
        data.get("ok") is True
        and data.get("verdict") == "human"
        and data.get("confidence", 0) >= 0.7
    )


# --- Flask ---------------------------------------------------------------
# @app.post("/contact")
# def contact():
#     if not is_human(request.form.get("behavior_nonce", "")):
#         abort(400, "Please submit the form again.")
#     ...

# --- Django --------------------------------------------------------------
# def contact(request):
#     if not is_human(request.POST.get("behavior_nonce", "")):
#         return HttpResponseBadRequest("Please submit the form again.")
#     ...

# --- FastAPI -------------------------------------------------------------
# @app.post("/contact")
# async def contact(behavior_nonce: str = Form("")):
#     if not is_human(behavior_nonce):
#         raise HTTPException(status_code=400, detail="Please submit the form again.")
#     ...

Flask, Django ja FastAPI

Ülalolev funktsioon ei sõltu raamistikust. Kolm kutsumiskohta on kommentaarina katke lõpus: Flask loeb vormisõnastikku, Django POST-andmeid, FastAPI vormiparameetrit.

Kui me pole kättesaadavad

Katke laseb külastaja läbi. Ekslikult tagasi lükatud klient maksab rohkem kui läbi lastud robot. Kui soovite vastupidist, tagastage veaharus väär — siis maksab tõrge teile esitusi.

Tehisintellekti agendid

Teatage agentide nägemistest sama mustriga telemeetria lõpp-punkti: üks POST ja sama päis.

Reeglite kohalik jõustamine Pythonist ei ole võimalik — kontrollitakse Ed25519 allkirja reeglipaketil. Pange enforcer rakenduse ette sidecarina või kasutage Cloudflare Workerit.