code-challenge-image.php
PNG image renderer for the code-challenge. Uses PHP-GD with the vendored DejaVuSans Bold TTF and a few naive anti-OCR distortions (per-character rotation, two random lines, scattered noise pixels).
Table of Contents
Functions
- creationell_captcha_code_challenge_font_usable() : bool
- Probes whether GD can actually render text with the vendored TTF font.
- creationell_captcha_render_code_image() : string
- Renders a PNG of the given code and returns the raw bytes. Caller is responsible for emitting headers (`Content-Type: image/png`, `Cache-Control: no-store`) and the body.
Functions
creationell_captcha_code_challenge_font_usable()
Probes whether GD can actually render text with the vendored TTF font.
creationell_captcha_code_challenge_font_usable() : bool
is_file() alone is not enough (ZP-2): a corrupted font or one swapped for
an unrelated/unreadable file still passes that check, but every
imagettftext() call against it then silently returns false and draws
nothing — the renderer would produce a blank white PNG with no error and
no log line. This probe draws into a throwaway 1-character canvas and
reports the real imagettftext() verdict, so both the renderer and
wp creacaptcha doctor (Check „Code-Challenge-Schriftart") can detect the
defect before a visitor ever requests /code-image.
A corrupted TTF fails identically for every glyph (the failure is a freetype parse error on the file, not a missing character), so probing with a single throwaway character reflects the file's real state.
Return values
boolcreationell_captcha_render_code_image()
Renders a PNG of the given code and returns the raw bytes. Caller is responsible for emitting headers (`Content-Type: image/png`, `Cache-Control: no-store`) and the body.
creationell_captcha_render_code_image(string $code) : string
Falls back to GD's built-in bitmap font 5 if the vendored TTF is missing
OR present but unusable (ZP-2: corrupted/swapped file — is_file() alone
cannot see that) — either way logs a one-line warning so the operator sees
the degradation instead of silently shipping a blank image.
Parameters
- $code : string
-
The code to render (4–8 chars expected; longer is trimmed implicitly by the width budget).