Tutorial Tutorial Tutorial Application Services Application Services Application Services ~10 phút ~10 min ~10 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Tích hợp Turnstile, WAF, & Bot Management Integrate Turnstile, WAF, & Bot Management ការរួមបញ្ចូល Turnstile, WAF, & Bot Management

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «Tích hợp Turnstile, WAF, & Bot Management» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Đọc phần tóm tắt và lưu ý trước — sau đó mở docs gốc để copy lệnh và cấu hình chi tiết.

This tutorial will guide you on how to integrate Cloudflare Turnstile, Web Application Firewall (WAF), and Bot Management. This combination creates a robust defense against various threats, including automated attacks and malicious login attempts.

វគ្គបណ្តុះបណ្តាលនេះនឹងរក្សាទុកអ្នកអំពីការរួមបញ្ចូល Cloudflare Turnstile, Web Application Firewall (WAF) និង Bot Management ។ ការរួមបញ្ចូលទាំងនេះបង្កើតការពារដ៏ស្រស់ស្អាតប្រឆាំងនឹងការជំរុញផ្សេងៗផ្សេងទៀតរួមទាំងការជំរុញដោយស្វ័យប្រវត្តិនិងការធ្វើតេស្តការចុះឈ្មោះដែលមានប្រសិទ្ធិភាព។

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
  • ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
  • Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។

Tài liệu gốc — rà soát lần cuối: over 1 year ago Official docs — last reviewed: over 1 year ago ឯកសារផ្លូវការ — ពិនិត្យចុងក្រោយ: over 1 year ago

Overview Overview Overview

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hướng dẫn này sẽ hướng dẫn bạn cách tích hợp Cloudflare Turnstile, Web Application Firewall (WAF) và Bot Management vào một hệ thống xác thực hiện có. Sự kết hợp này tạo ra một sự bảo vệ mạnh mẽ chống lại các mối đe dọa khác nhau, bao gồm các cuộc tấn công tự động và các nỗ lực đăng nhập độc hại.
This tutorial will guide you on how to integrate Cloudflare Turnstile, Web Application Firewall (WAF), and Bot Management into an existing authentication system. This combination creates a robust defense against various threats, including automated attacks and malicious login attempts.
វគ្គបណ្តុះបណ្តាលនេះនឹងជួយអ្នកក្នុងការរួមបញ្ចូល Cloudflare Turnstile, Web Application Firewall (WAF), និង Bot Management ទៅក្នុងប្រព័ន្ធសាកល្បងដែលមាន។ ការរួមបញ្ចូលទាំងនេះបង្កើតការពារដ៏ស្រស់ស្អាតប្រឆាំងនឹងការជំរុញផ្សេងៗផ្សេងទៀតរួមទាំងការជំរុញដោយស្វ័យប្រវត្តិនិងការធ្វើតេស្តការចុះឈ្មោះដែលមានប្រសិទ្ធិភាព។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Overview Overview Overview

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Để sử dụng WAF và Bot Management, trang web của bạn phải có DNS chỉ qua Cloudflare. Tuy nhiên, Turnstile có thể được sử dụng độc lập trên bất kỳ trang web nào, bao gồm cả những trang web không nằm trong mạng của Cloudflare. Hướng dẫn này sẽ bao gồm cách triển khai cả ba sản phẩm, nhưng bạn có thể tập trung vào Turnstile nếu trang web của bạn không nằm trên mạng Cloudflare.
To use WAF and Bot Management, your site must have its DNS pointing through Cloudflare. However, Turnstile can be used independently on any site including those not on Cloudflare's network. This tutorial will cover how to implement all three products, but you can focus on Turnstile if your site is not on Cloudflare's network.
ដើម្បីប្រើ WAF និង Bot Management របស់គេហទំព័ររបស់អ្នកគួរតែមាន DNS ដែលបង្ហាញតាម Cloudflare ។ ទោះជាយ៉ាងណាក៏ដោយ Turnstile អាចត្រូវបានប្រើដោយខ្លួនឯងនៅលើគេហទំព័រណាមួយរួមទាំងគេហទំព័រដែលមិននៅលើបណ្តាញរបស់ Cloudflare ។ វគ្គបណ្តុះបណ្តាលនេះនឹងបំពាក់អំពីរបៀបអនុវត្តទាំងបីផលិតផលប៉ុន្តែអ្នកអាចផ្តោតលើ Turnstile ប្រសិនបើគេហទំព័ររបស់អ្នកមិននៅលើបណ្តាញ Cloudflare ។
WAF, Bot Management, và Turnstile làm việc tốt với nhau bằng cách hoạt động trên các lớp khác nhau của ứng dụng:
WAF, Bot Management, and Turnstile work well together by operating on different layers of the application:
WAF, Bot Management, និង Turnstile ធ្វើការយ៉ាងល្អជាមួយគ្នាដោយធ្វើការនៅលើកម្រិតផ្សេងគ្នានៃកម្មវិធី:
  • WAF lọc lưu lượng truy cập độc hại dựa trên tín hiệu mạng.
  • Bot Management phân tích các yêu cầu để xác định và giảm thiểu các mối đe dọa tự động.
  • Turnstile kiểm tra các tín hiệu từ phía khách hàng và trình duyệt để phân biệt giữa người dùng và bot.
  • WAF filters malicious traffic based on network signals.
  • Bot Management analyzes requests to identify and mitigate automated threats.
  • Turnstile examines client-side and browser signals to distinguish between human users and bots.
  • WAF កម្រិតខុសគ្នានៃការដឹកជញ្ជូនដោយផ្អែកលើសញ្ញាបនប័ត្របណ្តាញ។
  • Bot Management អនុញ្ញាតឱ្យដោះស្រាយតម្រូវការដើម្បីរកឃើញនិងកាត់បន្ថយតម្រូវការដោយស្វ័យប្រវត្តិ។
  • Turnstile ពិនិត្យឡើងវិញសញ្ញាបនប័ត្រ client-side និង browser ដើម្បីបែកចាយរវាងអ្នកប្រើប្រាស់បុគ្គលិកនិង bots ។
Bằng cách kết hợp các biện pháp bảo mật phía máy chủ (WAF và Bot Management) và phía khách hàng (Turnstile), bạn có thể kết hợp nhiều lớp phòng thủ để tạo ra một hệ thống bảo vệ khó khăn cho kẻ tấn công để vượt qua.
By combining server-side (WAF and Bot Management) and client-side (Turnstile) security measures, you can combine multiple layers of defense to create a protection system that is difficult for attackers to circumvent.
ដោយការរួមបញ្ចូលគ្នានៃការសុវត្ថិភាពបន្ទាប់ពីផ្នែកបណ្តាញ (WAF និង Bot Management) និងបន្ទាប់ពីផ្នែកបណ្តាញ (Turnstile) អ្នកអាចរួមបញ្ចូលគ្នានៃការពារជាច្រើនដើម្បីបង្កើតប្រព័ន្ធការសុវត្ថិភាពដែលមានភាពងាយស្រួលសម្រាប់អ្នកជឿទុកចិត្តដើម្បីឆ្លងកាត់។

Trước khi bạn bắt đầu Before you begin មុនពេលដែលអ្នកចាប់ផ្តើម

Phần «Before you begin» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Before you begin" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «មុនពេលដែលអ្នកចាប់ផ្តើម» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
  • Bạn phải có tài khoản Cloudflare với access đến WAF và Bot Management (nếu sử dụng).
  • Một xác thực quản lý tuyến đường hiện có dựa trên JavaScript/TypeScript.
  • You must have a Cloudflare account with access to WAF and Bot Management (if using).
  • An existing JavaScript/TypeScript-based route handling authentication.
  • អ្នកត្រូវតែមានគណនី Cloudflare ជាមួយ access ទៅ WAF និង Bot Management (ប្រសិនបើបានប្រើ).
  • ការត្រួតពិនិត្យការត្រួតពិនិត្យដំណើរការដំណើរការដំណើរការដំណើរការដំណើរការដំណើរការដំណើរការដំណើរការដំណើរការ JavaScript / TypeScript ។
Hướng dẫn này sử dụng đăng nhập đơn giản form viết bằng HTML đơn giản để chứng minh cách tích hợp Turnstile vào ứng dụng của bạn. Trong backend, một đường dẫn xác thực bị ép, được viết bằng TypeScript, sẽ xử lý yêu cầu đăng nhập. Bạn có thể thay thế nó bằng ngôn ngữ của sự lựa chọn của bạn. Miễn là ngôn ngữ hoặc khung của bạn có thể thực hiện một yêu cầu bên ngoài HTTP để Turnstile's API, bạn có thể tích hợp Turnstile vào ứng dụng của bạn.
This tutorial uses a simple login form written in plain HTML to demonstrate how to integrate Turnstile into your application. In the backend, a stubbed out authentication route, written in TypeScript, will handle the login request. You may replace this with the language of your choice. As long as your language or framework is able to make an external HTTP request to Turnstile's API, you can integrate Turnstile into your application.
វគ្គបណ្តុះបណ្តាលនេះប្រើការចុះឈ្មោះ form ដែលត្រូវបានសរសេរដោយ HTML ដើម្បីបង្ហាញពីរបៀបដើម្បីរួមបញ្ចូល Turnstile ក្នុងកម្មវិធីរបស់អ្នក។ នៅលើផ្នែកខាងក្រៅ, ផ្លូវការត្រួតពិនិត្យការត្រួតពិនិត្យដែលត្រូវបានសរសេរនៅក្នុង TypeScript នឹងដំណើរការសំណួរការចុះឈ្មោះ។ អ្នកអាចផ្លាស់ប្តូរវាដោយភាសាដែលអ្នកចង់។ ប្រសិនបើភាសាឬគំរូរបស់អ្នកអាចធ្វើឱ្យសំណួរខាងក្រៅ HTTP ទៅ Turnstile's API អ្នកអាចរួមបញ្ចូល Turnstile ក្នុងកម្មវិធីរបស់អ្នក។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Cài đặt WAF và Bot Management Configure WAF and Bot Management ទាញយក WAF និង Bot Management

Phần «Cấu hình WAF và Bot Management» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Configure WAF and Bot Management" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទាញយក WAF និង Bot Management» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Nếu trang web của bạn nằm trên mạng Cloudflare và đăng ký gói Enterprise, bạn phải cấu hình WAF và Bot Management.
If your site is on Cloudflare's network and subscribed to an Enterprise plan, you must configure WAF and Bot Management.
ប្រសិនបើគេហទំព័ររបស់អ្នកគឺនៅលើបណ្តាញរបស់ Cloudflare ហើយបានចុះបញ្ចូលគម្រោងអាជីវកម្មអ្នកត្រូវកំណត់ WAF និង Bot Management ។

Giải quyết những thách thức đối với lưu lượng bot tiềm năng Issue challenges for potential bot traffic ការធ្វើតេស្តសម្រាប់ការធ្វើតេស្ត botpotential

Phần «Issue challenges for potential bot traffic» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Issue challenges for potential bot traffic" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការធ្វើតេស្តសម្រាប់ការធ្វើតេស្ត botpotential» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
  1. Trong bảng điều khiển Cloudflare, đi đến trang WAF.
  1. In the Cloudflare dashboard, go to the WAF page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ WAF ។
  1. Tạo một quy tắc tùy chỉnh mới WAF bằng cách chọn Edit expression:
  1. Create a new custom WAF rule by selecting Edit expression:
  1. ការបង្កើតកំណត់ WAF ថ្មីដោយជ្រើស Edit expression:
Field: "Bot Score" Operator: "less than or equal to" Value: "30" Action: "Managed Challenge"
Field: "Bot Score" Operator: "less than or equal to" Value: "30" Action: "Managed Challenge"
Field: "Bot Score" Operator: "less than or equal to" Value: "30" Action: "Managed Challenge"
Cấu hình này thách thức các yêu cầu với điểm số bot thấp, tận dụng tín hiệu mạng để xác định các mối đe dọa tiềm năng trước khi chúng tiếp cận ứng dụng của bạn. Bạn có thể tùy chỉnh ngưỡng điểm dựa trên trường hợp sử dụng cụ thể của bạn.
This configuration challenges requests with a low bot score, leveraging network signals to identify potential threats before they reach your application. You may customize the score threshold based on your specific use case.
ការកំណត់រចនាសម្ព័ន្ធនេះជំរុញទម្រង់ដែលមានកម្រិត bot ខ្ពស់ដោយប្រើអ៊ីនធឺណិតដើម្បីកាត់បន្ថយវិញ្ញាបនប័ត្របច្ចេកទេសដែលអាចរកបានមុនពេលដែលពួកគេបានចូលទៅក្នុងកម្មវិធីរបស់អ្នក។ អ្នកអាចកំណត់កម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិត។

Cài đặt Cloudflare Turnstile Set up Cloudflare Turnstile ទាញយក Cloudflare Turnstile

Phần «Thiết lập Cloudflare Turnstile» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Set up Cloudflare Turnstile" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទាញយក Cloudflare Turnstile» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Turnstile có thể được sử dụng trên bất kỳ trang web nào, bất kể nó có trên mạng của Cloudflare hay không:
Turnstile can be used on any site, regardless of whether it is on Cloudflare's network:
Turnstile អាចត្រូវបានប្រើនៅលើគេហទំព័រណាមួយដោយមិនទោះបីជាវានៅលើបណ្តាញរបស់ Cloudflare:
  1. Trong bảng điều khiển Cloudflare, đi đến trang Turnstile.
  1. In the Cloudflare dashboard, go to the Turnstile page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Turnstile ។
  1. Chọn Add widget và điền thông tin cần thiết.
  2. Thêm tên miền của bạn vào cấu hình Turnstile.
  3. Chọn Create
  1. Select Add widget and fill out the necessary information.
  2. Add your domain to the Turnstile configuration.
  3. Select Create.
  1. ចុច Add widget និងបញ្ចូលព័ត៌មានដែលត្រូវការ។
  2. បន្ថែមអាសយដ្ឋានរបស់អ្នកទៅកំណត់ Turnstile ។
  3. សូមជ្រើស Create ។
Turnstile thêm một lớp bảo mật bổ sung bằng cách phân tích các tín hiệu trình duyệt và khách hàng, bổ sung cho các kiểm tra bên máy chủ được thực hiện bởi WAF và Bot Management.
Turnstile adds an extra layer of security by analyzing browser and client-side signals, complementing the server-side checks performed by WAF and Bot Management.
Turnstile បានបន្ថែមកម្រិតបន្ថែមនៃការសុវត្ថិភាពដោយការដោះស្រាយអ៊ីនធឺណិតនិងអ៊ីនធឺណិតបន្ទាប់ពីអ៊ីនធឺណិតដើម្បីបន្ថែមការត្រួតពិនិត្យបន្ទាប់ពីអ៊ីនធឺណិតដែលធ្វើដោយ WAF និង Bot Management ។

Tích hợp Turnstile vào ứng dụng của bạn Integrate Turnstile into your application ការរួមបញ្ចូល Turnstile ក្នុងកម្មវិធីរបស់អ្នក

Phần «Tích hợp Turnstile into your ứng dụng» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Integrate Turnstile into your application" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការរួមបញ្ចូល Turnstile ក្នុងកម្មវិធីរបស់អ្នក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Có hai thành phần để triển khai Turnstile vào ứng dụng của bạn: widget Turnstile và logic xác thực phía máy chủ.
There are two components to implementing Turnstile into your application: the Turnstile widget and the server-side validation logic.
មានសមាសភាគពីរដើម្បីអនុវត្ត Turnstile នៅក្នុងកម្មវិធីរបស់អ្នក: ការ Turnstile widget និងការត្រួតពិនិត្យបង្វិលបង្វិល។

Thêm widget Turnstile vào login của bạn form Add the Turnstile widget to your login form Add the Turnstile widget to your login form

Phần «Thêm Turnstile widget vào login form» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Add the Turnstile widget to your login form" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Add the Turnstile widget to your login form» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thêm widget Turnstile vào login hiện tại của bạn form:
Add the Turnstile widget to your existing login form:
Add the Turnstile widget to your existing login form:
text
<form id="login-form">

  <input type="text" id="username" placeholder="Username" required />

  <input type="password" id="password" placeholder="Password" autocomplete="off" required />

  <div class="cf-turnstile" data-sitekey="<YOUR-SITE-KEY>"></div>

  <button type="submit">Log in</button>

</form>


<script

  src="https://challenges.cloudflare.com/turnstile/v0/api.js"

  async

  defer

></script>
Thay thế <YOUR-SITE-KEY> bằng khóa site Turnstile thực tế của bạn.
Replace <YOUR-SITE-KEY> with your actual Turnstile site key.
ការផ្លាស់ប្តូរ <YOUR-SITE-KEY> ដោយគោលការណ៍ Turnstile របស់អ្នក។

Xử lý yêu cầu login Handle the login request ការដោះស្រាយសំណួរ login

Phần «Xử lý login request» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Handle the login request" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការដោះស្រាយសំណួរ login» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trong lộ trình xác thực hiện có của bạn, thêm Turnstile xác thực:
In your existing authentication route, add Turnstile validation:
នៅលើដំណើរការអ៊ីនធឺណិតរបស់អ្នកបន្ថែម Turnstile ការត្រួតពិនិត្យ:
TypeScript Đánh giá
TypeScript
កុំព្យូទ័រ
text
async function validateTurnstileToken(

  ip: string,

  token: string,

  secret: string,

): Promise<boolean> {

  const response = await fetch(

    "https://challenges.cloudflare.com/turnstile/v0/siteverify",

    {

      method: "POST",

      headers: { "Content-Type": "application/json" },

      body: JSON.stringify({ ip, secret, response: token }),

    },

  );


  const outcome = await response.json();

  return outcome.success;

}


// Assume that this is a TypeScript route handler.

// You may replace this with a different implementation,

// based on your language or framework

export async function onRequestPost(context) {

  const { request, env } = context;

  const { username, password, token } = await request.json();


  // Validate Turnstile token

  const secretKey = env.TURNSTILE_SECRET_KEY;

  const ip = request.headers.get("CF-Connecting-IP");

  const turnstileValid = await validateTurnstileToken(ip, token, secretKey);

  if (!turnstileValid) {

    // Return back to the login page with an error message

    return Response.redirect("/login", 302, {

      headers: {

        Location: "/login?error=invalid-turnstile-token",

      },

    });

  }


  // Perform your existing authentication logic here

  const isValidLogin = await checkCredentials(username, password);


  if (isValidLogin) {

    return new Response(JSON.stringify({ message: "Login successful" }), {

      status: 200,

      headers: { "Content-Type": "application/json" },

    });

  } else {

    return new Response(JSON.stringify({ error: "Invalid credentials" }), {

      status: 401,

      headers: { "Content-Type": "application/json" },

    });

  }

}


async function checkCredentials(

  username: string,

  password: string,

): Promise<boolean> {

  // Your existing credential checking logic

}
Cài đặt này đảm bảo rằng mã thông báo Turnstile được xác nhận ở phía máy chủ trước khi tiến hành quá trình đăng nhập, thêm một lớp bảo mật bổ sung dựa trên tín hiệu ở phía khách hàng.
This setup ensures that the Turnstile token is validated on the server-side before proceeding with the login process, adding an extra layer of security based on client-side signals.
ការដំឡើងនេះធានាថា Turnstile token ត្រូវបានត្រួតពិនិត្យនៅលើផ្នែកផ្នែកបណ្តាញមុនពេលដំណើរការជាមួយនឹងដំណើរការការចុះឈ្មោះ, ការបន្ថែមកម្រិតបន្ថែមនៃការសុវត្ថិភាពដែលមានមូលដ្ឋានលើអ៊ីនធឺណិតអ៊ីនធឺណិត។

Testing Testing Testing

Phần «Testing» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Testing" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Testing» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Sau khi triển khai, bạn sẽ muốn kiểm tra tích hợp của bạn. Bởi vì điểm số bot của bạn sẽ thấp, bạn có thể sẽ không nhận được một thách thức. Tuy nhiên, bạn có thể thêm các quy tắc bổ sung khi cần thiết để buộc chuyển hướng đến trang thách thức. Một số lựa chọn để làm điều này là:
After deployment, you will want to test your integration. Because your bot score will be low, you will probably not receive a challenge. However, you can add additional rules as needed to force a redirect to the challenge page. Some options to do this are:
បន្ទាប់ពីការដំឡើងអ្នកនឹងចង់ធ្វើតេស្តការរួមបញ្ចូលរបស់អ្នក។ ដោយសារតែកំណត់កុំព្យូទ័ររបស់អ្នកនឹងមានកម្រិតខ្ពស់អ្នកនឹងមិនទទួលបានជម្រើស។ ទោះជាយ៉ាងណាក៏ដោយអ្នកអាចបន្ថែមច្បាប់ផ្សេងទៀតដែលត្រូវការដើម្បីអនុញ្ញាតឱ្យការបង្វិលទៅនឹងទំព័រជម្រើស។ មួយចំនួននៃជម្រើសដើម្បីធ្វើការនេះគឺ:
  1. Thêm quy tắc WAF mà luôn luôn chuyển tiếp địa chỉ IP của bạn đến trang thách thức.
  2. Thêm quy tắc WAF để kiểm tra sự hiện diện của một tham số truy vấn, chẳng hạn như ?challenge=true.
  1. Add a WAF rule that always forwards your IP address to the challenge page.
  2. Add a WAF rule that checks for the presence of a query parameter, such as ?challenge=true.
  1. បន្ថែមប្រព័ន្ធ WAF ដែលធ្វើឱ្យអាសយដ្ឋាន IP របស់អ្នកបានផ្ញើទៅទំព័រជម្រើស។
  2. បន្ថែមប្រព័ន្ធ WAF ដែលត្រួតពិនិត្យឱ្យមានទំហំសំណួរដូចជា ?challenge=true ។

Thực tiễn tốt nhất Best practices ការអនុវត្តល្អបំផុត

Phần «Best practices» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Best practices" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការអនុវត្តល្អបំផុត» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
  1. Luôn luôn xác nhận mã thông báo Turnstile ở phía máy chủ trước khi kiểm tra thông tin.
  2. Sử dụng các biến môi trường để lưu trữ thông tin nhạy cảm như khóa bí mật Turnstile của bạn.
  3. Thực hiện xử lý lỗi và ghi nhật ký thích hợp để theo dõi các vấn đề bảo mật tiềm tàng.
  1. Always validate the Turnstile token on the server-side before checking credentials.
  2. Use environment variables to store sensitive information like your Turnstile secret key.
  3. Implement proper error handling and logging to monitor for potential security issues.
  1. សូមប្រាកដ Turnstile នៅលើផ្នែកផ្នែកបណ្តាញមុនពេលត្រួតពិនិត្យឯកសារ។
  2. ប្រើទំហំបរិស្ថានដើម្បីរក្សាទុកព័ត៌មានសុវត្ថិភាពដូចជា Turnstile secret key របស់អ្នក។
  3. ការអនុវត្តការដោះស្រាយបញ្ហានិងការកំណត់បញ្ហានិងការត្រួតពិនិត្យបញ្ហានេះដើម្បីត្រួតពិនិត្យបញ្ហានេះសម្រាប់បញ្ហានេះ។
Bằng cách kết hợp Turnstile với WAF và Bot Management, bạn có thể tạo ra một hệ thống bảo mật ứng dụng của bạn trên lớp mạng, đồng thời cung cấp một lớp bảo vệ bổ sung bằng cách sử dụng tín hiệu phía khách hàng. Cách tiếp cận này làm cho nó khó khăn hơn đáng kể cho các diễn viên độc hại để tự động hóa các cuộc tấn công chống lại hệ thống đăng nhập của bạn.
By combining Turnstile with WAF and Bot Management, you can create a system that secures your application at the network layer, while also providing an extra layer of protection using client-side signals. This approach makes it significantly more difficult for malicious actors to automate attacks against your login system.
ដោយការរួមបញ្ចូល Turnstile ជាមួយ WAF និង Bot Management អ្នកអាចបង្កើតប្រព័ន្ធដែលការពារកម្មវិធីរបស់អ្នកនៅលើកម្រិតបណ្តាញក៏ដោយផ្តល់នូវកម្រិតបន្ថែមនៃការពារដោយប្រើអ៊ីនធឺណិត។ គោលបំណងនេះធ្វើឱ្យវាមានភាពងាយស្រួលខ្លាំងណាស់សម្រាប់អ្នកលក្ខណៈពិសេសដើម្បីស្វ័យប្រវត្តិការជួបប្រជុំប្រជុំប្រជុំប្រជុំប្រជុំប្រជុំប្រជុំប្រជុំប្រជុំរបស់អ្នក។

Tài nguyên Resources សមត្ថភាព

Phần «Resources» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Resources" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «សមត្ថភាព» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Nếu bạn quan tâm đến việc tùy chỉnh Turnstile, hãy tham khảo các tài nguyên dưới đây để biết thêm thông tin:
If you are interested in customizing Turnstile, refer to the resources below for more information:
ប្រសិនបើអ្នកមានអារម្មណ៍ក្នុងការកំណត់ផ្ទាល់ Turnstile, សូមពិនិត្យមើលឧបករណ៍ខាងក្រោមសម្រាប់ព័ត៌មានបន្ថែមទៀត:
  • Client-side rendering. Learn how to customize how and when Turnstile renders in your user interface, to better fit your application's needs and user experience.
  • Server-side validation. Learn how Turnstile's API works, including request parameters, as well as how to handle different types of responses, including error codes.
  • Turnstile Analytics. Learn how to view Turnstile's analytics in the Cloudflare dashboard. This includes metrics on the number of challenges issued, as well as the challenge solve rate (CSR).
  • Client-side rendering. Learn how to customize how and when Turnstile renders in your user interface, to better fit your application's needs and user experience.
  • Server-side validation. Learn how Turnstile's API works, including request parameters, as well as how to handle different types of responses, including error codes.
  • Turnstile Analytics. Learn how to view Turnstile's analytics in the Cloudflare dashboard. This includes metrics on the number of challenges issued, as well as the challenge solve rate (CSR).
  • Client-side rendering. Learn how to customize how and when Turnstile renders in your user interface, to better fit your application's needs and user experience.
  • Server-side validation. Learn how Turnstile's API works, including request parameters, as well as how to handle different types of responses, including error codes.
  • Turnstile Analytics. Learn how to view Turnstile's analytics in the Cloudflare dashboard. This includes metrics on the number of challenges issued, as well as the challenge solve rate (CSR).
json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/turnstile/","name":"Turnstile"}},{"@type":"ListItem","position":3,"item":{"@id":"/turnstile/tutorials/","name":"Tutorials"}},{"@type":"ListItem","position":4,"item":{"@id":"/turnstile/tutorials/integrating-turnstile-waf-and-bot-management/","name":"Integrate Turnstile, WAF, & Bot Management"}}]}

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗