diff --git a/docs/getting-started.md b/docs/getting-started.md index 33b8738..b4a0771 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -86,8 +86,8 @@ One line, and nothing in your forms changes: ```dotenv CAPTCHA_PROVIDER=turnstile -CAPTCHA_SITE_KEY=0x4AAA... -CAPTCHA_SECRET_KEY=0x4AAA... +CAPTCHA_SITE_KEY=example-key +CAPTCHA_SECRET_KEY=example-key ``` Forms bind to the canonical `captcha` field, and the widget writes it whichever provider is active. diff --git a/tests/Feature/Live/ProviderSmokeTest.php b/tests/Feature/Live/ProviderSmokeTest.php index 8323931..55ac6c4 100644 --- a/tests/Feature/Live/ProviderSmokeTest.php +++ b/tests/Feature/Live/ProviderSmokeTest.php @@ -87,8 +87,8 @@ function liveAdapter(Provider $provider, string $siteKey, string $secret): objec it('shows why the reCAPTCHA test keys are refused in production', function (): void { $adapter = liveAdapter( Provider::ReCaptchaV2, - '6LeIxAcTAAAAAJcZVRqyHh71UMIEGNQ_MXjiZKhI', - '6LeIxAcTAAAAAGG-vFI1TnRWxMZNFuojJ4WifJWe', + '6LeIxAcTAAAAAJcZVRqyHh71UMIEGNQ_MXjiZKhI', // Google's published test site key. ggignore gitleaks:allow + '6LeIxAcTAAAAAGG-vFI1TnRWxMZNFuojJ4WifJWe', // Google's published test secret. ggignore gitleaks:allow ); $result = $adapter->verify('not-a-real-token', VerificationContext::none());