Quickform CAPTCHA

From: Date: Fri, 08 Dec 2006 18:14:32 +0000
Subject: Quickform CAPTCHA
Groups: php.pear.general php.pear.general 
Request: Send a blank email to pear-general+get-26040@lists.php.net to get a copy of this message
Hoping someone can help. I am implementing a simple CAPTCHA for my forms but have come across a sticky problem. The relevant "abbreviated" code is shown below. The problem I am facing is in verifying the CAPTCHA. When the form initially loads a random image is generated by captchaImage() and sets the default for captcha_image, and sets the value of $_SESSION['register_captcha']. Then whenever the form is submitted to be validated the captcha function regenerates $_SESSION['register_captcha'] and the image, but before the checkCaptcha rule is verified. I believe this occurs because as the form reloads, quickform reads the form first and sets the defaults again (regenerating the CAPTCHA), and then validates the form which checks the rules. Sort of a chicken and egg problem. I could work around this by checking if $_SESSION['register_captcha'] is set and using the value, but then wouldn't be better if validation fails to regenerated the CAPTCHA, rather than reusing. e.g. credit: http://www.phpjabbers.com/captcha-image-verification-php19.html if(!isset($_SESSION["register_captcha"])) { $text = rand(100000,999999); $_SESSION["register_captcha"] = $text; } else { $text = $_SESSION["register_captcha"]; } //captcha image generation, credit: http://www.phpjabbers.com/captcha-image-verification-php19.html Whats important is that the image regenerate if the verification fails, but not upon every reload. So the questions: (1) Is there a way to prevent the regeneration of the CAPTCHA when the form reloads. What needs to be changed in what I have to allow this? (2) If I use the code above, and reuse $_SESSION["register_captcha"], how can this be regenerated if validation again fails? Thanks. Note that because of my website architecture all this appears on one page. // form $form =& new HTML_QuickForm('register','post'); $form->registerRule('checkCaptcha','callback','checkCaptcha'); $group[] =& HTML_QuickForm::createElement('text','captcha_input', '',array('size'=>'6')); $group[] =& HTML_QuickForm::createElement('static','captcha_image'); $group[] =& HTML_QuickForm::createElement('static','captcha_reason','',CAPTCHA_REASON); $form->addGroup($group,'captcha', 'Enter the code shown','',false); $form->addRule('captcha', 'Required','required', null); $form->addRule('captcha', 'Verify failed','checkCaptcha'); $form->setDefaults(array('captcha_image'=>captchaImage())); if($form->validate()) { process(); } else { echo $form->toHTML(); } // captcha rule callback function checkCaptcha($data) { if($data['captcha_input'] == $_SESSION['register_captcha']) { return true; } return false; } //captcha image generation, credit: http://www.phpjabbers.com/captcha-image-verification-php19.html function captchaImage() { $text = rand(100000,999999); $_SESSION["register_captcha"] = $text; $height = 25; $width = 85; $image = imagecreate($width, $height); $color = imagecolorallocate($image_p, 128, 128, 128); $font_size = 14; imagestring($image, $font_size, 5, 5, $text, $color); $tmp = md5($text . time()).'.png'; $tmpfile = sprintf('%s/%s', CAPTCHA_DIR, $tmp); imagepng($image, $tmpfile); imagedestroy($image); $url = sprintf('<img src="%s/%s" width="%d" height="%d" border="0" alt="Enter the code shown">', CAPTCHA_URL, $tmp, $width, $height); return $url; } }

« previous php.pear.general (#26040) next »