Problem/Motivation

Running Upgrade Status or PHPStan against CAPTCHA 2.0.10 on a Drupal 10 site preparing for Drupal 11 reports several issues across multiple files:

  • src/Element/Captcha.php extends the deprecated Drupal\Core\Render\Element\FormElement class, which is removed in Drupal 12. The replacement is FormElementBase per #3436275.
  • Multiple create() factory methods use new static() without a : static return type, triggering PHPStan's "Unsafe usage of new static()" warning.
  • Several create() methods lack a return type declaration entirely.
  • Missing use imports in CaptchaPoints.php for StateInterface.

Steps to reproduce

  1. Install CAPTCHA 2.0.10 on a Drupal 10.3+ site.
  2. Run Upgrade Status (/admin/reports/upgrade-status) or PHPStan.
  3. Observe the reported deprecations and warnings across the affected files.

Proposed resolution

  • Replace extends FormElement with extends FormElementBase in src/Element/Captcha.php.
  • Add : static return type declarations to all create() methods.
  • Replace new static() with new self() in create() methods where the class is not intended to be subclassed.
  • Add typed intermediate variables with @var docblocks in create() methods to satisfy static analysis.
  • Add missing use Drupal\Core\State\StateInterface import in CaptchaPoints.php.

Remaining tasks

The maintainers should review the attached patch for potential inclusion of the code.

Issue fork captcha-3576948

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

titacvetkovic created an issue. See original summary.

titacvetkovic’s picture

StatusFileSize
new6.56 KB

velmir_taky made their first commit to this issue’s fork.

velmir_taky’s picture

Status: Active » Needs review

Thank you @titacvetkovic for identifying and working on this issue! Your patch correctly addresses the core problems — the deprecated FormElement class and the missing : static return types.

I've built upon your work in the MR with a few adjustments:

What's kept from your patch:
- FormElement => FormElementBase replacement in Captcha.php
- Added : static return type to create() methods

What's different:
- Preserved new static() instead of changing to new self() — this is the standard Drupal pattern for factory methods, as it supports late static binding and allows subclasses to work correctly
- Kept the service calls inline in create() methods — the constructors already have proper type hints, so intermediate variables with @var annotations aren't needed here
- Extended the fix to 2 additional files that were missed: CaptchaSettingsForm.php and ImageCaptchaSettingsForm.php (9 files total)

All existing tests pass (2 unit, 4 kernel). PHPCS clean with Drupal + DrupalPractice standards.

anybody’s picture

Version: 2.0.10 » 2.x-dev
Priority: Normal » Major

Thanks, this is important and LGTM. Let's wait for further feedback before merging.

jwilson3’s picture

Would the changes in this MR allow the module to also be marked as D12 compatible?

I ask because the downstream module recaptcha_v3 has a dependency on this module, and had "NEXT_MAJOR" enabled in its .gitlab-ci.yml file, which is currently failing because captcha isnt yet marked as D12-compatible in captcha.info.yml

Related recaptcha_v3 issue #3580901: Pass GitLab CI pipeline.

anybody’s picture

Status: Needs review » Needs work

Doesn't https://www.drupal.org/node/3436275 mean we need to set ^10.3 as minimum supported Drupal version?

anybody’s picture

@jwilson3 would be great if you could review this to push D12 compatibility forward. Still we should have a dedicated issue for that.

PHPUnit (next major) still fails here, but yes let's do that in a different issue then, once this is fixed.

jerech made their first commit to this issue’s fork.

velmir_taky’s picture

Per #8: bumped core_version_requirement to ^10.3 || ^11 in both info.yml files (FormElementBase needs 10.3).

D12 left for a separate issue per #9.

velmir_taky’s picture

Status: Needs work » Needs review
rajab natshah’s picture

StatusFileSize
new125.77 KB
new60.34 KB

Tested !132 on Drupal 11.4.8 and 12.0.0-beta1 (PHP 8.5): settings, image CAPTCHA, points and the math challenge on the login form work on both. On 12 it also needs the info.yml and RequirementSeverity parts of the bot MR !137. Looks good to me.

Screenshot

Screenshot