RODO
Dokumentacja opisuje SCaptcha 2.3.0. Funkcje zależne od konfiguracji są oznaczone oddzielnie.
Scope
SCaptcha runs inside your WoltLab Suite installation. In normal operation, SoftCreatR does not receive verification data. Optional features and logging in your installation still need to be assessed separately.
Weryfikacja podstawowa
Każde zadanie używa niezależnej, kryptograficznie losowej soli o długości 32 bajtów. Instalacja WoltLab sprawdza sól, skrót, algorytm, rozwiązanie i HMAC w sesji, która wydała zadanie. Zadanie wygasa po 60 sekundach i nie wymaga zewnętrznego dostawcy CAPTCHA.
Opcjonalna analiza proxy
Domyślnie wyłączona. Po włączeniu SCaptcha wysyła publiczny adres IP do proxycheck.io po informacje o proxy, VPN lub Tor. SCaptcha 2.3.0 domyślnie wysyła tag=0; administrator może włączyć logowanie dostawcy. Adres IP jest przesyłany w obu przypadkach.
Logging at proxycheck.io
SCaptcha 2.3.0 sends tag=0 to proxycheck.io by default. Operators can opt in to provider-side positive-detection logs. The public IP address is transmitted for the lookup either way, and provider failure is not treated as a clean result.
Pliki cookie bezpieczeństwa
Znacznik przed wysłaniem i opcjonalny dowód tekstowy lub dźwiękowy są ważne 5 minut. Under-Attack używa podpisanego pliku cookie powiązanego z user-agentem przez 5–30 minut (domyślnie 10). Sentinel może przechować decyzję serwera o odmowie przez 10 minut i jest domyślnie wyłączony.
Optional browser checks
Behavior checks are off by default. The code contains pointer, movement, and scrolling checks, plus optional canvas, WebGL, and audio routines. Evaluation happens in the browser; results can affect local scoring and SCaptcha logs. This documentation therefore makes no blanket no-fingerprinting claim.
Analityka i retencja
Analityka żądań jest domyślnie włączona i może przechowywać powiązywalne dane operacyjne: IP, user-agent, żądanie, sieć, lokalizację, powody i przesłaną telemetrię. Retencja wynosi domyślnie 90 dni i może mieć od 1 do 3650 dni. Wyłączenie nie usuwa istniejących wpisów ani eksportów.
Responsibility and data processing
In a normal self-hosted installation, SoftCreatR does not process visitor data on your behalf. If you enable proxycheck.io or another external service, assess and document that relationship separately. Your hosting and support setup can create additional roles.
Deployment checklist
Enable only the options you need. Update privacy and cookie notices, restrict access to analytics and logs, and test the actual form integration before launch.