Hi,
I’m having issues with the captcha in my eform contact us forms. About half the time the contact form fails the captcha check on form submission. I think the problem has to do with my host having a server cluster environment. I’m wondering if this problem could arise if one server loaded up a page and another server in the cluster when to validate the form submission.
Does anyone have a fix for this problem, or anything I can try to fix it?
Thanks.
-
☆ A M B ☆
- 24,524 Posts
The captcha code generated is stored in the SESSION. When the user submits the form, the value he entered for the captcha is compared with the value in the SESSION. In the case of clustered servers, you can’t be sure the user will get the same server when he submits the form, so the SESSION will be different if he gets a different server.
Probably the best way to handle this is to save it to a cookie, or to the database.
Unless your hosting provider can arrange for the sessions to be saved to a static location.
I’ve been messing with this trying to make CAPTCHA work in 0.9.7. If it went to the db, how could it best be tied to the specific user who’s logging on?
Bob
-
☆ A M B ☆
- 24,524 Posts
I would imagine you’d need a cookie with a key to the database, grab the key from the cookie, get the captcha from the database using the key, and compare against the POST value.
I thought 097 was going to use the database for SESSIONs by default; this would eliminate the problem altogether.
Quote from: sottwell at Mar 12, 2008, 05:14 AM
I would imagine you’d need a cookie with a key to the database, grab the key from the cookie, get the captcha from the database using the key, and compare against the POST value.
I thought 097 was going to use the database for SESSIONs by default; this would eliminate the problem altogether.
With 0.9.7, I’ve failed to get the veriword function to save a SESSION variable and have it available later -- ever. It would be great if they were saved to the db but, unless there’s a new method for saving and retrieving them, I don’t think they’re going to the DB yet.
Bob
-
MODX Staff
- 10,725 Posts
The captcha will be totally replaced in 0.9.7. Various captcha methods can be provided as an extension to the product, and someone has already proposed a comprehensive extension for this with several options.
Also, let’s try to keep 0.9.7 discussions in the MODx Next forum. This really isn’t appropriate for the eForm support topics and probably quite confusing for some.
Quote from: OpenGeek at Mar 12, 2008, 09:39 PM
The captcha will be totally replaced in 0.9.7. Various captcha methods can be provided as an extension to the product, and someone has already proposed a comprehensive extension for this with several options.
Also, let’s try to keep 0.9.7 discussions in the MODx Next forum. This really isn’t appropriate for the eForm support topics and probably quite confusing for some.
Sorry, I thought it was peripherally related to the clustered server problem and I’m still looking for ways to make CAPTCHA more reliable but you’re right, this discussion belongs elsewhere.
Bob