Re: Quickform CAPTCHA

From: Date: Sat, 09 Dec 2006 02:56:10 +0000
Subject: Re: Quickform CAPTCHA
References: 1 2 3 4  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-26048@lists.php.net to get a copy of this message
Thanks Justin. Don't want to "beat a dead horse," but its a question of simplicity and completeness. It would seem that the proper way to handle this is to regenerate the CAPTCHA on validation error, rather than saving and reusing the saved SESSION var. It is not likely, but you can imagine that a bot can simply try to enter numbers in increasing order until the form is accepted. But, I suppose that mechanisms can be put in place to prevent repeated registration attempts from the same IP, e.g. reset the entire form, therefore resetting the CAPTCHA. And I suppose for the bot to know that we are seeking numbers in the CAPTCHA input, would suggest that we have already lost the battle to form spammers. :) In any case, I agree that the approach suggested is sufficient for my case. Thanks for answering and listening. Thanks. Justin Patrin wrote:
On 12/8/06, David L <david-newsphp@ackee.com> wrote:
Thats just it. I don't see any possible way to regenerate the captcha upon validation error alone. Thing is whenever the form is submitted the captcha will regenerate thus changing the session var and causing the captcha check to fail. Again the rule fails because it occurs during the validation check which occurs after the form has been reloaded.
So don't do that. Check if the session var is set and don't regenerate. Use the saved captcha text.
I am not sure if what I want to do is possible here. The problem lies in the setDefaults area, which calls the captcha function upon form load. Should the setDefaults be applied again when the form is submitted? Can we somehow control the setting of the session var beyond saving it if it is already set?
This is just a question of logic. You just have to run things at the right time. Actually, you should be perfectly fine only calling setDefaults if validation doesn't happen. The defaults don't have anything to do with the submitted values, really.
Thanks. Justin Patrin wrote:
On 12/8/06, David L <david-newsphp@ackee.com> wrote:
Hoping someone can help. I am implementing a simple CAPTCHA for my
forms
but have come across a sticky problem. The relevant "abbreviated" code is shown below. The problem I am facing is in verifying the CAPTCHA. When the form initially loads a random image is generated by captchaImage() and sets the default for captcha_image, and sets the value of $_SESSION['register_captcha']. Then whenever the form is submitted
to be
validated the captcha function regenerates
$_SESSION['register_captcha']
and the image, but before the checkCaptcha rule is verified. I
believe
this occurs because as the form reloads, quickform reads the form
first
and sets the defaults again (regenerating the CAPTCHA), and then validates the form which checks the rules. Sort of a chicken and egg problem. I could work around this by checking if
$_SESSION['register_captcha'] is
set and using the value, but then wouldn't be better if validation
fails
to regenerated the CAPTCHA, rather than reusing. e.g. credit: http://www.phpjabbers.com/captcha-image-verification-php19.html
        if(!isset($_SESSION["register_captcha"])) {
            $text = rand(100000,999999);
            $_SESSION["register_captcha"] = $text;
        } else {
            $text = $_SESSION["register_captcha"];
        }
//captcha image generation, credit: http://www.phpjabbers.com/captcha-image-verification-php19.html
If you really want to regenerate on validation failure I suggest you do just that. Don't regenerate if the session value is set, then if validation fails unset the session var and regenerate.


« previous php.pear.general (#26048) next »