We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24278
    • 165 Posts
    Quote from: TobyL at Dec 15, 2006, 09:17 AM

    Ha, glad to see that that bit of code is protecting us grin
    But seriously,.. I’d like to see what’s causing it. is it too much to ask you to post your full chunks, snippet call and whatever else you’ve set up for the form? I’d like to have a look at it and make sure this warning is not a false positive as they say...

    The Snippet call and form code is as under...
    Snippet call
    [!ap_eForm? &formid=`inviteFriendForm` &category=`Invite Friend` &from=`[email protected]` &fromname=`ap` &tpl=`ap_inviteFriendForm` &report=`ap_inviteFriendFormReport` &thankyou=`ap_inviteFriendFormSuccess` &vericode=`0` &subject=`[+name+] has sent you an invitation` &sendirect=`1`!]
    
    
    Form code
    <p>Fields marked <strong>*</strong> are required.</p>
    [+validationmessage+]
    <form method="post" id="inviteFriendForm">
    <p class="formWrap">
    <input type="hidden" name="formid" value="inviteFriendForm" />
    
    <label for="name">Your Name*: </label><br />
    <input class="textbox" type="text" name="name" id="name" size="30" eform="Your Name::1" /><br />
    <label for="name">Your Email*: </label><br />
    <input class="textbox" type="text" name="semail" id="semail" size="30" eform="Your Email::1" /><br />
    
    <input type="hidden" name="email" id="email" value="[+email+]">
    <label>Email addresses of your friends*: </label><br />
    <input class="textbox" type="text" name="invite1" id="invite1" size="30" eform="1st email address of your friend:email:1" onchange="updateEmail()" /><br />
    <input class="textbox" type="text" name="invite2" id="invite2" size="30" eform="2nd email address of your friend:email:0" onchange="updateEmail()" /><br />
    <input class="textbox" type="text" name="invite3" id="invite3" size="30" eform="3rd email address of your friend:email:0" onchange="updateEmail()" /><br />
    
    <label for="comments">Comments: </label><br />
    <textarea cols="50" rows="10" name="comments" id="comments" eform="Comments:html:0"></textarea><br />
    
    
    <input class="button" type="submit" value="Send Email" /><br />
    
    
    
    <script>
    	function updateEmail() {
    		// get form elements
    		var f = document.forms['inviteFriendForm'];
    		var email = f.elements['email'];
    		var t1 = f.elements['invite1'];
    		var t2 = f.elements['invite2'];
    		var t3 = f.elements['invite3'];
    		
    		// store emails 1 to 3 inside an array
    		emails = []; 
    		emails[emails.length] = t1.value
    		if (t2.value) emails[emails.length] = t2.value;
    		if (t3.value) emails[emails.length] = t3.value;
    		
    		// save emails to email field
    		email.value = emails.join(",");
    	}
    </script>
    
    
    </p>
    </form>
    
      • 30223
      • 1,010 Posts
      Thanks, I’ll have a look at it over the weekend.
        • 24278
        • 165 Posts
        Quote from: TobyL at Dec 15, 2006, 06:45 PM

        Thanks, I’ll have a look at it over the weekend.

        Have you had a chance to look into the code? I still need help grin.
          • 30223
          • 1,010 Posts
          Woke up a bit too early this morning so took the opportunity to look at this...

          eForm protects against the tampering with hidden field values. It does this by reading the value of hidden field values at parse time (so before any values are read from POST) and building a validation rule based on that value. In your case the value at parse time is empty and gets filled using javascript. eForm however checks against the empty value and thus throws a "tampering attempt" error.

          There’s a simple, be it a bit counter intuitive, solution. If you give the hidden field your own validation rule eForm will use that instead. So in your case if you replace the email field in your form template with something like this, you’ll find that the error disappears (if the other email fields are filled in properly)
          <input type="hidden" name="email" id="email" value="[+email+]" eform="Email::1:Some email fields are incorrect:#REGEX /^[a-z0-9.-_]+?@[a-z0-9.-_@,]+/i">
          


          The regex rule gives you a very rudimentary validation on email like values. You may want to improve on that.
            • 24278
            • 165 Posts
            Thanks Toby, for looking into the issue. I appreciate it.

            I will try your solution.

            Happy holidays and Wonderful 2007.

            best regards,
            -Raavi