1
Hey!-
Have you read MadFish ideas about CAPTCHA and alternatives?
Well, he had a great idea. That is, all forms are (or should be) generated via XoopsForm object. He suggested that every form could include an invisible text field. Users can't fill it because they don't see it, but bots should bite.
I was thinking about hacking the XoopsForm object so that EVERY FORM is automatically protected this way.
The problem is checking the form, there are two solutions:
1 - every module should include some code to check the form
2 - Modify header.php to do this check.
The code should be someting like:
Quote:
if ( !empty($_POST['trap'])) {
xoops_redirect etc etc
}
What do you think? Ideas? Suggestions?