More thoughts on multiple form submit control (was Re: [PHP] Example needed)
| From: | Steve Edberg | Date: | Tue, 01 Aug 2000 22:33:22 +0000 |
| Subject: | More thoughts on multiple form submit control (was Re: [PHP] Example needed) | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-9588@lists.php.net to get a copy of this message | ||
Ya know, you could generalize the technique below and make it useful for forms where you aren't saving the data in a database:
Create a database table that looks something like this:
+-------------+-----------+
| script_name | char() | | form_name | char() || TestField | char(32) | | submit_time | timestamp | +-------------+-----------+ This table could be used for all of your submission scripts, even those with multiple forms on a page. Then, just store the md5() hash in this table and check submits against this table as below, but using the additional fields: 'SELECT count(*) as found '. 'FROM your_table '. "WHERE TestField = '$TestField'". " AND script_name = '$SCRIPT_NAME'". " AND form_name = 'form_1'" If you check against the timestamp, you could then limit submissions to, say, once per day, once a week, or whatever. You could use this table to track activity, and - be adding a column and saving HTTP_REFERER - where the users are coming from. With this approach, you would not need to change existing table structures, if you are saving form data as below, and you could use it even if you weren't saving submissions in a database - say, for a form-mail script. - steve, again At 2:12 PM -0700 8/1/00, Steve Edberg wrote:
At 12:33 PM -0700 8/1/00, Chris Kovalcik wrote:+--- "They've got a cherry pie there, that'll kill ya" ------------------+Hi, Does someone have a quick example on how to prevent multiple submits from a form? Say, a 30 sec delay until the same person can submit the same form again? Thanks, ChrisThis might not work in your case, but what I have often done is this: I'm assuming you're storing form data in a database. Just create an extra 32-byte character field in your database (indexed, if possible, to make SELECTs faster), that is an md5 hash of the form data. That is: $TestField = md5(strtolower(implode('', $FormDataArray))); On occasion I've used an ereg_replace to squeeze out spaces as well- that would make the values 'Wendell p Snarzboggle' and 'wendell P snarzboggle' appear the same.Before inserting the data, create the md5 hash and then see if that exists in your table: $ResultId = mysql_db_query( $YourDatabase, 'SELECT count(*) as found '. 'FROM your_table '. "WHERE TestField = '$TestField'", $LinkId); If found > 0, then there's a duplicate. One advantage of this method is that you have more control over what constitutes a duplicate - as above you can ignore case and/or embedded spaces. You could also eliminate punctuation, make data into a standard form (eg, replace 'Dr.', 'Dr ', 'doctor ' with 'Dr. '), or what have you. The disadvantage is that it requires somewhat more disk space and requires an extra SELECT (although a 'SELECT count(*)' on an indexed field should be very fast). Hope that helps - - steve edberg
| Steve Edberg University of California, Davis | | sbedberg@ucdavis.edu Computer Consultant | | http://aesric.ucdavis.edu/ http://pgfsun.ucdavis.edu/ |+-------------------------------------- FBI Special Agent Dale Cooper ---+