【问题标题】:Same page Captcha validation using AJAX使用 AJAX 进行同一页面验证码验证
【发布时间】:2013-05-01 15:11:39
【问题描述】:

好的,所以我一直在研究这段代码。我从 SecurImages 的预设代码开始,并一直在调整它以尝试验证验证码并提交表单。问题是,我们的表单被提交给创建它的第三方站点并将数据提交到他们自己的数据库中,而我无权访问他们的代码。他们使用几个隐藏字段来提取信息,例如,他们链接到他们的一般网站,然后检查页面是否通过表单提交,然后检查提交详细信息以确定提交信息的表单和位置。我的问题是,我可以让验证码验证而不提交表单,或者我可以提交表单而不验证验证码。我似乎不能两者兼得。目前,我可以正确验证验证码,但表单无法正确提交。

        function processForm()
    {
        new Ajax.Request('<?php echo $_SERVER['PHP_SELF'] ?>', {
            method: 'post',
            parameters: $('zoho1').serialize(),
            onSuccess: function(transport) {
                try {
                    var r = transport.responseText.evalJSON();


                    if (r.error == 0) {
                    alert ("You are the man!");


                    } else {
                        alert("There was an error with your submission.\n\n" + r.message);


                    }
                } catch(ex) {
                    alert("There was an error parsing the json");


                }
            },
            onFailure: function(err) {
                alert("Ajax request failed");
            }
        });
        return false;
    }

当用户单击提交按钮时,它会运行此 AJAX 查询。

function process_si_zoho1()
{
if ($_SERVER['REQUEST_METHOD'] == 'POST' && @$_POST['do'] == 'contact') {
    // if the form has been submitted

    foreach($_POST as $key => $value) {
        if (!is_array($key)) {
            // sanitize the input data
            if ($key != 'LEADCF3') $value = strip_tags($value);
            $_POST[$key] = htmlspecialchars(stripslashes(trim($value)));
        }
    }
    /*
    $name    = @$_POST['First Name'] . @$_POST['Last Name'];    // name from the form
    $email   = @$_POST['Email'];   // email from the form
    $mainphone     = @$_POST['Phone'];     // url from the form
    $mobile = @$_POST['Mobile']; // the message from the form
    $state = @$_POST['State']; // the state from the form
    $type = @$_POST['LEADCF4']; // Type of student from form
    $enrollment = @$_POST['LEADCF2']; //Expected enrollment
    $time = @$_POST['LEADCF5']; //Intended enrollment status
    $degree = @$_POST['LEADCF6']; //Intended degree
    $message =  @$_POST['LEADCF3']; //How did you hear about TTU?
    $comments = @$_POST['Description']; //Comments*/
    $captcha = $_POST['captcha_code']; // the user's entry for the captcha code
    //$name    = substr($name, 0, 64);  // limit name to 64 characters

    $errors = array();  // initialize empty error array

    if (isset($GLOBALS['DEBUG_MODE']) && $GLOBALS['DEBUG_MODE'] == false) {
        // only check for errors if the form is not in debug mode




        if (strlen($email) == 0) {
            // no email address given
            $errors['email_error'] = 'Email address is required';
        } else if ( !preg_match('/^(?:[\w\d]+\.?)+@(?:(?:[\w\d]\-?)+\.)+\w{2,4}$/i', $email)) {
            // invalid email format
            $errors['email_error'] = 'Email address entered is invalid';
        }

        if (strlen($message) < 10) {
            // message length too short
            $errors['message_error'] = 'Please enter a message';
        }
    }

    // Only try to validate the captcha if the form has no errors
    // This is especially important for ajax calls
    if (sizeof($errors) == 0) {
        require_once dirname(__FILE__) . '/securimage.php';
        $securimage = new Securimage();

        if ($securimage->check($captcha) == false) {
            $errors['captcha_error'] = 'Incorrect security code entered';
        }
    }

   if (sizeof($errors) == 0) {
        // no errors, send the form
       // header('http://crm.zoho.com/crm/WebToLeadForm');

       /*if (isset($GLOBALS['DEBUG_MODE']) && $GLOBALS['DEBUG_MODE'] == false) {
            //send the message with mail()
            header('location:http://www.tntemple.edu/request-information-online-learning-thank-you');
        }*/

        $return = array('error' => 0, 'message' => 'OK');
        die(json_encode($return));
    } else {
        $errmsg = $captcha_error;
        foreach($errors as $key => $error) {
            // set up error messages to display with each field
            $errmsg .= " - {$error}\n";
        }

        $return = array('error' => 1, 'message' => $errmsg);
        die(json_encode($return));
    }


} // POST
} // function process_si_zoho1()

该函数在页面加载时立即运行,并检查页面是否已提交。被注释掉的变量最初是代码的一部分,但我认为我们不需要它们,所以我把它们注释掉了。原始代码旨在将表单的结果邮寄给收件人,但我们需要它“返回 true”以提交表单。

<form action="https://crm.zoho.com/crm/WebToLeadForm" id="zoho1" method="POST" name="leadForm" onsubmit="return processForm()">

这是带有操作和 onSubmit 的表单。我希望我已经足够清楚了。谢谢您的帮助。我对 HTML 之外的编程还很陌生,但我大部分时间都学得很快。

此外,理想情况下,我们将在成功提交表单后重定向到另一个 URL。

【问题讨论】:

  • 您不能使用header() 函数发送表单,它只会重定向浏览器。如果您希望他们在您的网站上填写一张表格并发布到另一个网站,您将需要使用 cURL 或类似的东西来代表他们发出 http 请求。如果您不想这样做,那么表单将不得不在没有验证码的情况下直接发布给供应商,因为您实际上不能让他们的浏览器通过 1 次提交来执行 2 个表单。
  • 如果验证码验证,有没有办法让 processForm() 函数的值返回 true?这似乎是主要问题。我已经放弃了 header() 函数,只是忘记从代码中编辑它,但它被注释掉了。
  • @drew010 如果验证码验证,有没有办法让 processForm() 函数的值返回 true?
  • 并非如此,因为 processForm() 中的 ajax 调用是异步的,所以函数会立即返回 false,并且一旦请求成功完成,就会调用 ajax 请求中的 onSuccess 回调,这将在 onsubmit 事件之后发生表格已经完成了。
  • @drew010 谢谢,我想通了。我必须添加字符串 document.forms['formname'].submit();最终,我试图做的是让表单提交给操作。不过感谢您的帮助。

标签: php javascript ajax captcha


【解决方案1】:

基本上,为了返回表单的动作,我只是添加了

if (r.error == 0) {
reloadCaptcha()
document.forms['formname'].submit()

它返回到action字段,就好像在没有参数的情况下按下了提交按钮,“return false”

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2012-04-18
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多