Java Module
Installation
Add the dependency:
1
2
3
4
5
<dependency>
<groupId>com.botbye</groupId>
<artifactId>java-module</artifactId>
<version>4.0.0</version>
</dependency>
Configuration
Phishing lives in its own dedicated BotbyePhishingClient, separate from the evaluate Botbye client. It is identified by a public, browser-safe clientKey, so it needs no server key — construct it standalone and reuse it. On construction it makes a one-off, best-effort server-integration init handshake that reports this server-side integration to BotBye; it is non-blocking and never affects your request path.
BotbyePhishingConfig takes 2 values: endpoint (optional, defaults to https://verify.botbye.com) and clientKey.
Getting clientKey
clientKey is the public, browser-safe identifier of your phishing project. It travels in the asset URL path, so it is safe to expose — no secret token and no Base64 encoding are required.
Find it on the Get Started screen of your phishing project in the BotBye dashboard.
1
2
3
4
5
6
7
8
9
10
import com.botbye.phishing.BotbyePhishingClient;
import com.botbye.phishing.BotbyePhishingConfig;
import com.botbye.phishing.BotbyePhishingCatcher;
BotbyePhishingClient<Void> phishing = new BotbyePhishingClient<>(
new BotbyePhishingConfig.Builder()
.endpoint("https://verify.botbye.com")
.clientKey("<public-client-key>")
.build()
);
Usage
Anti-phishing needs two routes on your own origin: an SVG route — the URL your client code passes to getCatcher({ url }) — and a PNG route that the SVG references. The paths are arbitrary, so name them like ordinary static assets and let the route decide the format. A path that spells out the vendor or the feature (/api/phishing/…) is what a copied page is searched for and stripped of, and a format query param on the pixel URL reads the same way.
On the SVG route, pass innerPngUrl — the absolute URL of your PNG route: the returned SVG embeds it as its tracking pixel. It is required: the SVG catcher takes it as a constructor argument, so an SVG asset without one does not compile, and a blank one is rejected on the spot rather than reaching the wire. Build that URL from your own host — image_id is owned by the SDK and is not read from the forwarded query. skipExecution defaults to true, the script-less SVG; pass false only for browsers predating crossorigin on svg <image> (Chrome 118, Firefox 114, Safari 17.2), where the script-driven variant is the one that still reports.
These examples forward no query: format, image_id and executable are set by the call itself, and only module_name / module_version pass through from the browser's pixel query — which a catcher mounted on your own routes never receives.
If you would rather not read the request yourself, bind it once: BotbyePhishingClient.withExtractor(config, request -> new BotbyePhishingRequestInfo(origin, referer, query)) gives a BotbyePhishingClient<YourRequest> whose fetchCatcher(request, BotbyePhishingCatcher.svg(…)) takes the raw request instead of origin / referer. The extractor is then the only thing that reads the request — headers and query alike.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
// Absolute URL of your PNG route — the SVG catcher references it through innerPngUrl.
static final String PNG_CATCHER_URL = "https://your-site.example/your-image-route.png";
// Serve /your-image-route.svg with BotbyePhishingCatcher.svg(PNG_CATCHER_URL) and /your-image-route.png
// with BotbyePhishingCatcher.png() — the route picks the catcher, nothing is read off the query.
void serveCatcher(HttpServletRequest request, HttpServletResponse resp, BotbyePhishingCatcher catcher)
throws IOException {
String origin = request.getHeader("Origin");
String referer = request.getHeader("Referer");
BotbyePhishingResponse response;
try {
response = phishing.fetchCatcher(catcher, origin, referer);
} catch (Exception e) {
resp.sendError(500, e.getMessage() != null ? e.getMessage() : "internal error");
return;
}
if (response.getError() != null) {
resp.sendError(502, response.getError().getMessage());
return;
}
String contentType = response.getHeaders().getOrDefault("Content-Type", "image/png");
resp.setStatus(response.getStatus());
resp.setContentType(contentType);
resp.getOutputStream().write(response.getBody());
}
Settings
Configuration parameters for phishing integration:
| Setting | Description | Required | Default Value |
|---|---|---|---|
| endpoint | Host of the phishing API | no | https://verify.botbye.com |
| clientKey | Public client-key of your phishing project | yes | - |