Re: Quickform CAPTCHA

From: Date: Fri, 08 Dec 2006 20:46:49 +0000
Subject: Re: Quickform CAPTCHA
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-26045@lists.php.net to get a copy of this message
On 12/8/06, David L <david-newsphp@ackee.com> wrote:
Hoping someone can help. I am implementing a simple CAPTCHA for my forms but have come across a sticky problem. The relevant "abbreviated" code is shown below. The problem I am facing is in verifying the CAPTCHA. When the form initially loads a random image is generated by captchaImage() and sets the default for captcha_image, and sets the value of $_SESSION['register_captcha']. Then whenever the form is submitted to be validated the captcha function regenerates $_SESSION['register_captcha'] and the image, but before the checkCaptcha rule is verified. I believe this occurs because as the form reloads, quickform reads the form first and sets the defaults again (regenerating the CAPTCHA), and then validates the form which checks the rules. Sort of a chicken and egg problem. I could work around this by checking if $_SESSION['register_captcha'] is set and using the value, but then wouldn't be better if validation fails to regenerated the CAPTCHA, rather than reusing. e.g. credit: http://www.phpjabbers.com/captcha-image-verification-php19.html
        if(!isset($_SESSION["register_captcha"])) {
            $text = rand(100000,999999);
            $_SESSION["register_captcha"] = $text;
        } else {
            $text = $_SESSION["register_captcha"];
        }
//captcha image generation, credit: http://www.phpjabbers.com/captcha-image-verification-php19.html
If you really want to regenerate on validation failure I suggest you do just that. Don't regenerate if the session value is set, then if validation fails unset the session var and regenerate. -- Justin Patrin

« previous php.pear.general (#26045) next »