【问题标题】:custom captcha submits form even if code is not correct即使代码不正确,自定义验证码也会提交表单
【发布时间】:2014-07-27 15:27:43
【问题描述】:

我正在使用自定义验证码,但即使代码不正确,它也会提交表单 这是索引页面主代码

$(document).ready(function() { 

 $('#Send').click(function() {  

        // name validation

        var nameVal = $("#name").val();
        if(nameVal == '') {

            $("#name_error").html('');
            $("#name").after('<label class="error" id="name_error">Please enter your name.</label>');
            return false
        }
        else
        {
            $("#name_error").html('');
        }

        /// email validation

        var emailReg = /^([\w-\.]+@([\w-]+\.)+[\w-]{2,4})?$/;
        var emailaddressVal = $("#email").val();

        if(emailaddressVal == '') {
            $("#email_error").html('');
            $("#email").after('<label class="error" id="email_error">Please enter your email address.</label>');
            return false
        }
        else if(!emailReg.test(emailaddressVal)) {
            $("#email_error").html('');
            $("#email").after('<label class="error" id="email_error">Enter a valid email address.</label>');
            return false

        }
        else
        {
            $("#email_error").html('');
        }

        $.post("post.php?"+$("#MYFORM").serialize(), {

        }, function(response){

        if(response==1)
        {
            $("#after_submit").html('');
            $("#Send").after('<label class="success" id="after_submit">Your message has been submitted.</label>');
            change_captcha();
            clear_form();
        }
        else
        {
            $("#after_submit").html('');
            $("#Send").after('<label class="error" id="after_submit">Error ! invalid captcha code .</label>');
        }


    });

    return false;
 });

 // refresh captcha
 $('img#refresh').click(function() {  

        change_captcha();
 });

 function change_captcha()
 {
    document.getElementById('captcha').src="get_captcha.php?rnd=" + Math.random();
 }

 function clear_form()
 {
    $("#name").val('');
    $("#email").val('');
    $("#message").val('');
 }
}); 

index.php 代码(session_start 在文件开头)

<form action="#" name="MYFORM" id="MYFORM">
<label>Name</label>
<input name="name" size="30" type="text" id="name">
<br clear="all" />
<label>Email</label>
<input name="email" size="30" type="text" id="email">
<br clear="all" />
<label>Message</label>
<textarea id="message" name="message"></textarea>
<br clear="all" />  
<div id="wrap" align="center">
    <img src="get_captcha.php" alt="" id="captcha" />       
    <br clear="all" />
    <input name="code" type="text" id="code">
</div>
<img src="refresh.jpg" width="25" alt="" id="refresh" />        
<br clear="all" /><br clear="all" />
<label>&nbsp;</label>
<input value="Send" type="submit" id="Send">
</form> 

post.php 代码

session_start();    
if(@$_REQUEST['code'] || @strtolower($_REQUEST['code']) == strtolower($_SESSION['random_number']))
{               
    echo 1;// submitted         
}
else
{
    echo 0; // invalid code
}

get_captcha.php 文件

session_start();
$string = '';
for ($i = 0; $i < 5; $i++) {
$string .= chr(rand(97, 122));
}
$_SESSION['random_number'] = $string;
$dir = 'fonts/';
$image = imagecreatetruecolor(165, 50);
$num = rand(1,2);
if($num==1)
{
$font = "Capture it 2.ttf"; // font style
}
else
{
$font = "Molot.otf";// font style
}
$num2 = rand(1,2);
if($num2==1)
{
$color = imagecolorallocate($image, 113, 193, 217);// color
}
else
{
$color = imagecolorallocate($image, 163, 197, 82);// color
}

$white = imagecolorallocate($image, 255, 255, 255); // background color white
imagefilledrectangle($image,0,0,399,99,$white);

imagettftext ($image, 30, 0, 10, 40, $color, $dir.$font, $_SESSION['random_number']);

header("Content-type: image/png");
imagepng($image);

这是完整的代码http://download1473.mediafire.com/ef2uaexp2hmg/3j63qbbq7xiwryi/captcha.rar

【问题讨论】:

    标签: php captcha


    【解决方案1】:

    (基于其他答案)

    你犯了一个大错误。你为什么要用@符号来隐藏错误?那只是糟糕的编码。您可能在某个地方遇到了更大的问题,而您永远不会知道这一点。如果这是一种习惯,那么当您处理关键数据时呢?你会忽略错误吗?

    对于你的实际代码,你想在 if 语句中首先使用isset() 吗?这就是你的意思吗?

    你的代码应该是这样的......

    session_start();    
    if(isset($_REQUEST['code']) && strtolower($_REQUEST['code']) == strtolower($_SESSION['random_number']))
    {               
        echo 1;// submitted         
    }
    else
    {
        echo 0; // invalid code
    }
    

    【讨论】:

      【解决方案2】:

      post.php代码中应该有&&,否则只要$_REQUEST['code']不为空就会执行echo 1。

      session_start();    
      if(@$_REQUEST['code'] && @strtolower($_REQUEST['code']) == strtolower($_SESSION['random_number']))
      {               
          echo 1;// submitted         
      }
      else
      {
          echo 0; // invalid code
      }
      

      【讨论】:

        猜你喜欢
        • 1970-01-01
        • 1970-01-01
        • 2016-06-15
        • 1970-01-01
        • 2018-07-02
        • 1970-01-01
        • 2015-10-13
        • 1970-01-01
        • 2021-11-28
        相关资源
        最近更新 更多