Problem/Motivation
#2492681: Properly disable page and render cache disabled page cache for regular Captchas (image & math). #3311443: [PP-1][2.x] Expose information about cacheability for each selectable captcha type at least try to inform the users about it.
But best would be to be able to cache pages even with a captcha present. So the question is, if there's no technical way to solve that, for example by loading the captcha container using AJAX instead of placing it on the page directly.
Could lazy builders help?
https://www.drupal.org/docs/drupal-apis/render-api/auto-placeholdering
https://drupalsun.com/philipnorton42/2022/05/01/drupal-9-using-lazy-buil...
https://www.hashbangcode.com/article/drupal-10-using-lazy-builder-create...
Could this core issue help?
#2578855: Form tokens are now rendered lazily, allow forms to opt in to be cacheable
Ideas welcome!
Steps to reproduce
Proposed resolution
Remaining tasks
- Discuss possible solutions
- Implement & write tests
- Release
Comments
Comment #2
anybodyHoneypot is implementing an AJAX solution for this, perhaps we can do something similar here? #2820400: Use JS for time limit protection on cached pages
Comment #3
anybodyI guess this is really important for performance and the climate ;)
Comment #4
anybodyComment #5
macsim commented+1 for the AJAX implementation.
Since I added my pages in the CDN, my users have an error saying that they are providing an incorrect answer to the captcha.
Comment #6
anybodyPOSTPONED on #3314766: [2.x] Improve the CAPTCHA form markup and use twig files for more flexibility, where possible as this is a 2.x issue.
Comment #7
anybodyComment #8
anybodyComment #9
anybodyComment #10
anybodyComment #11
anybodyComment #12
anybodyComment #13
mlncn commentedAgree this is major. At the very least we need to document that CDNs must be disabled on CAPTCHA pages.
Comment #14
anybodyCould lazy builders help?
https://www.drupal.org/docs/drupal-apis/render-api/auto-placeholdering
https://drupalsun.com/philipnorton42/2022/05/01/drupal-9-using-lazy-buil...
https://www.hashbangcode.com/article/drupal-10-using-lazy-builder-create...
I'd really be happy, if someone with huge Drupal knowledge could have a look at this for feedback - as it surely affects a ton of Drupal installations regarding performance. My 16Y Drupal experience is sadly still not enough to be sure we go the right way here ... ;D Sorry.
Comment #15
anybodyComment #16
anybody@japerry any thoughts on this perhaps, as super experienced Drupal Dev? I think this would be super useful for many projects out there, having CTA forms on regular pages.
Comment #17
omarlopesinoI would like to help with this topic as I need to allow caching in a website with high traffic. As it has been suggested, we should find a way to do the validation through AJAX. The problem with the server-side validation is that the captcha session ID gets lost.
Does it make sense to generate the captcha session ID on the JS side through an AJAX request, and then send the captcha session ID as a form value in the submit? It would also require some validation in client side to check it is created by the system and not maliciously.
Please let me know your thoughts about this, I will investigate further and in the case I find a stable solution I would come up with a merge request.
Comment #18
anybodyhttps://www.drupal.org/node/3442559
Comment #19
geek-merlinThis is great stuff!
IIRC this is the core use case of "lazy builder" and "auto placeholdering".
- Implement the captcha in a lazybuilder and add caching information max-age=0
- Then auto-placeholdering kicks in, which
- allows the page cache to cache the page without the captcha
- if bigpipe is enabled, serves the page with a placeholder, and has it replaced via js
- https://www.drupal.org/docs/drupal-apis/render-api/auto-placeholdering
- https://www.droptica.com/blog/drupal-bigpipe-using-lazy-builders-2023/
- https://www.youtube.com/watch?v=SdcNXbEeymw
Only somebody(tm) has to code it.
Comment #20
anybodyThanks @geek-merlin happy to have you on board here! 🎉 And nice to see you like the idea.
Maybe we(tm) can solve this together, puzzling our knowledge together.
I'd really like to get this solved (plus some other important fixes in captcha). It's pain to see how many people use this module, but nobody really cares... ;) or at least pays :P
We're in a large project currently, but if you should find some time in the next months to tackle this with us, feel free to ping me or @Grevil.
PS: I also think this will speed up many projects using e.g. webforms globally on all / many pages, killing their cache this way.
Comment #21
geek-merlinThere are lots of good lazybuilder docs and articles, and examples like this. You should look how far this gets you and can pm me with an MR.
Comment #22
murat_kekic commentedI believe lazy builders might not work in this case, as they are primarily designed for render arrays.
For reference, there's a related support discussion about lazy builders not being supported by form elements.
#lazy_builder is not supported by forms
Comment #23
joshmillerJust commenting that I found this issue while investigating possible ways to make our newly launched redesign that includes recaptcha on most pages cacheable again. Varnish seems to still be working, but Drupal isn't keeping any full page in cache for people logged in (which bypasses varnish).