https://sonarly.com/issue/7148?type=bug
Google reCAPTCHA v3 rejects the origin `trippinc.twenty.com` because customer subdomains aren't registered in the reCAPTCHA admin console. The missing `.catch()` on the `grecaptcha.execute()` promise causes an unhandled rejection that surfaces as a user-facing error snackbar.
Fix: Added a `.catch()` handler to the `window.grecaptcha.execute()` promise in `useRequestFreshCaptchaToken.ts`. When Google reCAPTCHA fails (e.g., "invalid origin" because the workspace subdomain isn't registered in the reCAPTCHA admin console), the handler resets `isRequestingCaptchaToken` to `false` so the app doesn't get stuck. This prevents the unhandled rejection from bubbling up through `PromiseRejectionEffect`, which was showing a confusing error snackbar to users and reporting noise to Sentry.
Added a test that verifies `isRequestingCaptchaToken` is reset when `grecaptcha.execute()` rejects, following the exact test patterns in the existing test file.
**Note:** The full fix also requires a configuration change — add `*.twenty.com` to the Google reCAPTCHA admin console's allowed domains for the site key. Without this, reCAPTCHA will continue to fail for all customer subdomains, though the code fix ensures it fails silently instead of showing errors to users.