Skip to content

[TEN-173] Replace deprecated captcha endpoints with public api - #149

Merged
yangwang-okta merged 1 commit into
auth0:mainfrom
TSLarson:ten-173
Sep 28, 2026
Merged

yangwang-okta merged 1 commit into
auth0:mainfrom
TSLarson:ten-173

Conversation

@TSLarson

@TSLarson TSLarson commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

By submitting a PR to this repository, you agree to the terms within the Auth0 Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Migrates getBotDetectionSetting in analyzer/tools/auth0.js from the deprecated internal /api/anomaly/captchas endpoint to the two new public API endpoints:

  • GET /api/v2/attack-protection/bot-detection challenge policies, allowlist, monitoring mode
  • GET /api/v2/attack-protection/captcha active captcha provider config

The legacy endpoint returned a single combined object; the public API splits this across two endpoints. Both are fetched in parallel and merged so downstream checks (checkBotDetectionSetting) continue to receive the same unified shape with no changes required there.

References

  • Internal ticket: TEN-173
  • Deprecation of GET /api/anomaly/captchas in favor of GET /api/v2/attack-protection/bot-detection and GET /api/v2/attack-protection/captcha

Testing

The merged response object has the same shape as the legacy internal endpoint returned, so all existing checkBotDetectionSetting logic is unaffected.

Tested manually against a live tenant: both endpoints return 200 and the merged object contains the expected fields (bot_detection_level, challenge_password_policy, challenge_passwordless_policy, challenge_password_reset_policy, allowlist, monitoring_mode_enabled, active_provider_id).

  • This change adds test coverage for new/changed/fixed functionality

Checklist

  • I have added documentation for new/changed functionality in this PR or in auth0.com/docs
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used, if not the default branch

@TSLarson
TSLarson requested a review from a team as a code owner September 24, 2026 12:37
@yangwang-okta
yangwang-okta merged commit f849a36 into auth0:main Sep 28, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants