It will be nice if it is possible to optionally configure the persistence for each form separately. This will allow, for example, to set node or comment submission forms to skip captcha once the user has passed captcha on that form, while presenting a captcha every time the user login form is presented. At the moment, if persistence (for all forms) is set to 'skip after one success', an anonymous visitor has to correctly answer the captcha on the login form only once to be able to guess user names and passwords many times thereafter. This seems unsafe. Instead there should be a default persistence setting for all forms (as it is in the current D5 version) and the ability to optionally set persistence setting for each form as desired.

Comments

wundo’s picture

Issue summary: View changes
Status: Active » Closed (won't fix)