From 5f5b24f1fba319e32439d6e7efdd117195d540a6 Mon Sep 17 00:00:00 2001 From: Adam Wright Date: Fri, 18 Sep 2026 07:29:54 +0000 Subject: [PATCH] Correct the docs that said beta has no captcha Beta now enforces Turnstile on /chat/guest/, using production's keys, so two places that said otherwise were wrong: the beta README's "leaving the secret unset makes the middleware bypass itself, which is what we want", and the deploy script's closing line telling an operator the captcha is absent by design. The README line was doubly wrong after this branch: unset no longer bypasses, it refuses to start. Co-Authored-By: Claude Opus 5 --- deploy/beta/README.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/deploy/beta/README.md b/deploy/beta/README.md index f0e880a..52b287c 100644 --- a/deploy/beta/README.md +++ b/deploy/beta/README.md @@ -5,8 +5,16 @@ are registered for `reactome.org`, not beta) and no Postgres — the LangGraph checkpointer falls back to `MemorySaver`, so conversations live in memory and are lost on restart. Chat history and the `/chat/personal` route come later. -Leaving `CLOUDFLARE_SECRET_KEY` unset makes the captcha middleware bypass itself, -which is what we want: the Turnstile site key is bound to `reactome.org`. +**Turnstile is enforced on `/chat/guest/`** since 2026-09-18, using production's +keys -- the site key now lists `beta.reactome.org` as well as `reactome.org`, so +beta no longer needs to run without one. Rotating the key in production means +rotating it here too, or beta breaks. + +Leaving `CLOUDFLARE_SECRET_KEY` unset used to make the middleware bypass itself +silently. It now refuses to start instead, unless `CHAT_REQUIRES_HUMAN=0` says +deliberately that a deployment wants no human check. "There is captcha +middleware" and "the chat is gated" were previously different statements with +nothing to tell them apart. ## 1. Embeddings