Skip to content

CCSAAS-5490 initiate upload recaptcha GraphQL - #623

Open
jhadobe wants to merge 1 commit into
october-accs-integrationfrom
CCSAAS-5490-upload-captcha
Open

jhadobe wants to merge 1 commit into
october-accs-integrationfrom
CCSAAS-5490-upload-captcha

Conversation

@jhadobe

@jhadobe jhadobe commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Purpose of this pull request

This pull request (PR) documents the new Enable for Presigned Upload Google reCAPTCHA setting for the initiateUpload mutation (CCSAAS-5490).

Affected pages

whatsnew
Documented optional reCAPTCHA validation for the initiateUpload mutation.

@jhadobe jhadobe self-assigned this Oct 2, 2026
@jhadobe jhadobe added the major-update Significant updates to content label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🔍 Linter Report

Click to expand full report
═══════════════════════════════════════════════════════════════
                     LINTER REPORT
═══════════════════════════════════════════════════════════════

Generated: 2026-10-02T22:59:27.361Z
Mode: Full Linting (all rules + dead links check)
Target Directory: /home/runner/work/commerce-webapi/commerce-webapi
Skipped Rules:
  - check-frontmatter → src/pages/includes
  - missing-heading → src/pages/includes

───────────────────────────────────────────────────────────────

Files to process: 2


═══════════════════════════════════════════════════════════════
                        SUMMARY
═══════════════════════════════════════════════════════════════

  📁 Files processed:    2
  📄 Files with issues:  0
  ❌ Total errors:       0
  ⚠️  Total warnings:     0
  📋 Total issues:       0

Result: ✅ PASSED - All files passed linting successfully!

═══════════════════════════════════════════════════════════════

This comment was automatically generated by the linter bot.


## reCAPTCHA validation

Guest shoppers can call the `initiateUpload` mutation without a customer token, for example, to attach an image to a guest return. To limit automated upload requests, merchants can require Google reCAPTCHA validation on this mutation. This setting is disabled by default. To enable it, set [**Enable for Presigned Upload**](https://experienceleague.adobe.com/en/docs/commerce-admin/config/security/google-recaptcha-storefront) in **Stores** > **Configuration** > **Security** > **Google reCAPTCHA Storefront** > **Storefront**.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm guessing merchants can enable reCAPTCHA for logged in customers as well. I would rewrite this paragraph a bit to de-emphasize guest shoppers, and just mention somewhere that you don't supply a customer for guest users.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

major-update Significant updates to content

Projects

Status: 👍 Approved

Development

Successfully merging this pull request may close these issues.

3 participants