Quickform CAPTCHA
| From: | David L | Date: | Fri, 08 Dec 2006 18:12:15 +0000 |
| Subject: | Quickform CAPTCHA | ||
| Groups: | php.pear.general php.pear.general | ||
| Request: | Send a blank email to pear-general+get-26041@lists.php.net to get a copy of this message | ||
Hoping someone can help. I am implementing a simple CAPTCHA for my forms
but have come across a sticky problem. The relevant "abbreviated" code is
shown below.
The problem I am facing is in verifying the CAPTCHA. When the form
initially loads a random image is generated by captchaImage() and sets the
default for captcha_image, and sets the value of
$_SESSION['register_captcha']. Then whenever the form is submitted to be
validated the captcha function regenerates $_SESSION['register_captcha']
and the image, but before the checkCaptcha rule is verified. I believe
this occurs because as the form reloads, quickform reads the form first
and sets the defaults again (regenerating the CAPTCHA), and then validates
the form which checks the rules. Sort of a chicken and egg problem.
I could work around this by checking if $_SESSION['register_captcha'] is
set and using the value, but then wouldn't be better if validation fails
to regenerated the CAPTCHA, rather than reusing. e.g. credit:
http://www.phpjabbers.com/captcha-image-verification-php19.html
if(!isset($_SESSION["register_captcha"])) {
$text = rand(100000,999999);
$_SESSION["register_captcha"] = $text;
} else {
$text = $_SESSION["register_captcha"];
}
//captcha image generation, credit:
http://www.phpjabbers.com/captcha-image-verification-php19.html
Whats important is that the image regenerate if the verification fails,
but not upon every reload.
So the questions:
(1) Is there a way to prevent the regeneration of the CAPTCHA when the
form reloads. What needs to be changed in what I have to allow this? (2)
If I use the code above, and reuse $_SESSION["register_captcha"], how can
this be regenerated if validation again fails?
Thanks.
Note that because of my website architecture all this appears on one page.
// form
$form =& new HTML_QuickForm('register','post');
$form->registerRule('checkCaptcha','callback','checkCaptcha');
$group[] =&
HTML_QuickForm::createElement('text','captcha_input',
'',array('size'=>'6')); $group[] =&
HTML_QuickForm::createElement('static','captcha_image'); $group[] =&
HTML_QuickForm::createElement('static','captcha_reason','',CAPTCHA_REASON);
$form->addGroup($group,'captcha', 'Enter the code shown','',false);
$form->addRule('captcha', 'Required','required', null);
$form->addRule('captcha', 'Verify failed','checkCaptcha');
$form->setDefaults(array('captcha_image'=>captchaImage()));
if($form->validate()) {
process();
} else {
echo $form->toHTML();
}
// captcha rule callback
function checkCaptcha($data) {
if($data['captcha_input'] == $_SESSION['register_captcha']) {
return true;
}
return false;
}
//captcha image generation, credit:
http://www.phpjabbers.com/captcha-image-verification-php19.html
function captchaImage() {
$text = rand(100000,999999);
$_SESSION["register_captcha"] = $text;
$height = 25;
$width = 85;
$image = imagecreate($width, $height); $color =
imagecolorallocate($image_p, 128, 128, 128); $font_size = 14;
imagestring($image, $font_size, 5, 5, $text, $color);
$tmp = md5($text . time()).'.png';
$tmpfile = sprintf('%s/%s',
CAPTCHA_DIR,
$tmp);
imagepng($image, $tmpfile);
imagedestroy($image);
$url = sprintf('<img src="%s/%s" width="%d"
height="%d" border="0"
alt="Enter the code shown">',
CAPTCHA_URL,
$tmp,
$width,
$height);
return $url;
}
}