【问题标题】:Limit user to filling out form only once限制用户只填写一次表格
【发布时间】:2011-09-12 23:33:24
【问题描述】:

我希望创建一个简单的网络表单,并且我想“劝阻”用户不要多次填写表单。表单的指标用于统计分析,每次用户填写并重新提交表单时,结果集通常会发生变化,从而进行分析。

虽然我们不想阻止重试(知道已完成重试也是有价值的信息),但我们确实想警告用户:“嘿,看起来你最近填写了这个。你是确定要重新填写吗?”

这里需要注意的是,我们希望尽量减少收集的个人身份信息的数量。

使用客户端 IP 存储 cookie 是最好/最简单的方法吗?或者是否有一种简单的方法可以将 IP 服务器端缓存 xx 时间,这样我们就可以运行比较,说“嘿,我想这个人今天早些时候试图访问我。我应该发出警告”。

【问题讨论】:

  • 也许 cookie 是最好的方法;当用户在代理服务器后面访问您的应用程序时,IP 阻止可能会导致一些误报

标签: c# webforms


【解决方案1】:

恒定值的cookie就足够了,IP也不行。如果用户没有清除 cookie,您就会知道该用户已经填写了表单。

【讨论】:

    【解决方案2】:

    我以前使用过的简单解决方案是在用户填写的 HTML 表单中放置一个不可见的时间戳。如果您两次提交相同的时间戳,您就知道是重新提交。

    如果您担心被篡改,您可以随时混淆/加密时间戳。

    这也可能只是一个随机的唯一标识符,我选择了一个时间戳来了解用户填写表单(大致)花了多长时间。

    这基本上类似于会话 cookie,但可能被认为更“私密”,因为客户端的计算机无需记住任何内容,因此不能像某些跟踪 cookie 广告网站那样使用它。

    缺点是这种方法要求客户端/代理不缓存表单,因为它“更改”每个请求。

    【讨论】:

      【解决方案3】:

      这里有两个问题,用户多次点击提交按钮,用户在另一个时间点填写表单。

      对于第二个,我可以看到两个非常简单的解决方案会推荐一个会话 cookie,只是 cookie 用户机器,不要让他们再次看到表单,或者要求提供诸如电子邮件地址之类的信息,然后签入如果之前使用过 DB,则忽略新表单的详细信息。

      对于多表单提交,您可以使用此代码,这将禁用按钮 onclick。

         //
         // Disable button with no secondary JavaScript function call.
         //
         public static void DisableButtonOnClick(Button ButtonControl)
         {
             DisableButtonOnClick(ButtonControl, string.Empty);
         }
      
          // Disable button with a JavaScript function call.
          //
          public static void DisableButtonOnClick(Button ButtonControl, string ClientFunction)
          {
              var sb = new StringBuilder(128);
      
              // If the page has ASP.NET validators on it, this code ensures the
              // page validates before continuing.
              sb.Append("if ( typeof( Page_ClientValidate ) == 'function' ) { ");
              sb.Append("if ( ! Page_ClientValidate() ) { return false; } } ");
      
              // Disable this button.
              sb.Append("this.disabled = true;");
      
              // If a secondary JavaScript function has been provided, and if it can be found,
              // call it. Note the name of the JavaScript function to call should be passed without
              // parens.
              if (!String.IsNullOrEmpty(ClientFunction))
              {
                  sb.AppendFormat("if ( typeof( {0} ) == 'function' ) {{ {0}() }};", ClientFunction);
              }
      
              // GetPostBackEventReference() obtains a reference to a client-side script function 
              // that causes the server to post back to the page (ie this causes the server-side part 
              // of the "click" to be performed).
              sb.Append(ButtonControl.Page.GetPostBackEventReference(ButtonControl) + ";");
      
              // Add the JavaScript created a code to be executed when the button is clicked.
              ButtonControl.Attributes.Add("onclick", sb.ToString());
          }
      

      【讨论】:

        猜你喜欢
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 2021-01-16
        • 1970-01-01
        • 2018-01-05
        • 1970-01-01
        • 1970-01-01
        相关资源
        最近更新 更多