<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[FrontAccounting forum — Securimage CAPTCHA Integration into FA]]></title>
	<link rel="self" href="https://frontaccounting.com/punbb/extern.php?action=feed&amp;tid=3341&amp;type=atom" />
	<updated>2014-06-16T04:51:53Z</updated>
	<generator>PunBB</generator>
	<id>https://frontaccounting.com/punbb/viewtopic.php?id=3341</id>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=20204#p20204" />
			<content type="html"><![CDATA[<p>Upgrade to v2.3.21 and then modify the changes in the first post in this thread to suit the current version of the files that need to be changed.</p><p>The devs were expected to have made it into an extension by now.</p>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2014-06-16T04:51:53Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=20204#p20204</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=20012#p20012" />
			<content type="html"><![CDATA[<p>i m using version FrontAccounting 2.3.19.</p>]]></content>
			<author>
				<name><![CDATA[zin]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=19140</uri>
			</author>
			<updated>2014-05-30T18:44:33Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=20012#p20012</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=20010#p20010" />
			<content type="html"><![CDATA[<p>Which version of FA are you using and what platform and LAMP version is it being deployed in.<br />Have you downloaded the securimage library and integrated it in as well?</p>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2014-05-30T03:45:57Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=20010#p20010</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=20009#p20009" />
			<content type="html"><![CDATA[<p>Not working, after login main page blank with blue background. what happened.</p>]]></content>
			<author>
				<name><![CDATA[zin]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=19140</uri>
			</author>
			<updated>2014-05-29T23:35:54Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=20009#p20009</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=13369#p13369" />
			<content type="html"><![CDATA[<p>Thanks Janusz, no hurry. Meanwhile, have posted updated <a href="http://www.apmuthu.com/bugfixes/LoginsDelay_Fix.zip">LoginDelay Fix</a> for <a href="http://mantis.frontaccounting.com/view.php?id=1785"><strong>BugPost 1785</strong></a></p>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2012-09-17T11:33:15Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=13369#p13369</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=13368#p13368" />
			<content type="html"><![CDATA[<p>Your is captcha integration is good piece of code, so I would like to make it available as optional extension. Anyway it will take me some time due to other works in progress I have just now, so please be patient.</p><p>Janusz</p>]]></content>
			<author>
				<name><![CDATA[itronics]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=89</uri>
			</author>
			<updated>2012-09-17T09:57:40Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=13368#p13368</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=13362#p13362" />
			<content type="html"><![CDATA[<p>If it doesn&#039;t make it to the code base, can it find a place in the Wiki? (Placed in Wiki)</p><p>Now that the failed login delay feature has been introduced in v2.3.12, the above code needs to modified carefully in the light of changes to login.php and other files listed above.</p>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2012-09-15T08:23:41Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=13362#p13362</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=13361#p13361" />
			<content type="html"><![CDATA[<p>Configurable Delay after specified login attempts is quite nice. May need to store login attempts somewhere or stale failed logins would false trigger.</p><p>Since the captcha is only on initial login (not for timeouts) and is configurable in the config.php would it&#039;s integration into the base code prove troublesome? The download size would become huge due tot he audio scripts - maybe another config variable for controlling audio enablement on captcha would be desirable. Yes the CAPTCHA proved very tiresome during repetitive testing....</p><p>Can it be encapsulated as an optional plugin (bundled with securimage code) ?</p>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2012-09-15T08:22:08Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=13361#p13361</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=13355#p13355" />
			<content type="html"><![CDATA[<p>I have ready to publish another simple fix, maybe better suitable for hosted FA accounts. The fix introduces configurable delay after some failed login attempts. Captcha activated on every login attempt seems to be more restrictive for real user than for automated&nbsp; spam scripts using OCR tools. Thank you very much for the contribution. <br />Janusz</p>]]></content>
			<author>
				<name><![CDATA[itronics]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=89</uri>
			</author>
			<updated>2012-09-14T17:37:35Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=13355#p13355</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Securimage CAPTCHA Integration into FA]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=13354#p13354" />
			<content type="html"><![CDATA[<p>Would you like the <a href="http://www.phpcaptcha.org">Securimage</a> CAPTCHA integration to get into the code base for the current v2.3.11+ in mercurial repo?</p><p>Details at:<br /><a href="http://mantis.frontaccounting.com/view.php?id=1783">Feature Posted At Bugs (#1783) Site</a></p><p><strong>Download in debian with:</strong><br /></p><div class="codebox"><pre><code>cd /var/www
wget -O securimage.tar.gz https://github.com/dapphp/securimage/tarball/master
mkdir -p /var/www/frontac/securimage
tar -xzf securimage.tar.gz -C /var/www/frontac/securimage --strip-components=1</code></pre></div><p><strong>FA Securimage Integration notes:</strong></p><p>FA uses it&#039;s own session name computed using the domain / uri string it was installed at.<br />FA&#039;s JavaScripts for Ajax and other HttpRequests use the default PHPSESSID session name.<br />The Securimage SQLite DB is not being used by default andonly SESSION variables are used.<br />The Audio files account for over 95% of the securimage download size.</p><p><strong>CAPTCHA Session variables used:</strong></p><div class="codebox"><pre><code>$_SESSION = Array (
......

    [securimage_code_disp]  =&gt; Array ( [default] =&gt; bnGp24 ) 
    [securimage_code_value] =&gt; Array ( [default] =&gt; bngp24 ) 
    [securimage_code_ctime] =&gt; Array ( [default] =&gt; 1347630909)

) </code></pre></div><p><strong>The files:</strong></p><p>Place the securimage library in the <strong>securimage</strong> folder at the webroot.<br />Copy the securimage/securimage_show.php to securimage/securimage_show_n.php</p><p>File: securimage/securimage_show_n.php<br />Insert at the very top after the opening PHP tag:<br /></p><div class="codebox"><pre><code>$sn = (isset($_GET[&#039;sn&#039;]) ? trim($_GET[&#039;sn&#039;]) : &#039;PHPSESSID&#039;);
$oldsess = session_name($sn);</code></pre></div><p>Append at the very last:<br /></p><div class="codebox"><pre><code>session_name($oldsess);</code></pre></div><p>File: config.default.php<br />Append before last closing PHP tag:<br /></p><div class="codebox"><pre><code>/*  Should FA use CAPTCHA for login form?
    false for no       true for yes
    Get the securimage code at https://github.com/dapphp/securimage/zipball/master
    Extract the contents into the securimage folder under the webroot.
*/

    $use_captcha_for_login = false;</code></pre></div><p>The above variable must be set to true for CAPTCHA use.<br />It defaults to false for backwards compatibility.</p><br /><p>File: access/login.php<br />Insert at Line 102:<br /></p><div class="codebox"><pre><code>//         Use CAPTCHA only for fresh login and not for timeouts
        if ($use_captcha_for_login &amp;&amp; !($login_timeout)) 
        {
            start_row();
?&gt;
            &lt;td colspan=&quot;2&quot;&gt;
                &lt;img id=&quot;siimage&quot; 
                    style=&quot;border: 1px solid #000; margin-right: 15px&quot; 
                    src=&quot;securimage/securimage_show_n.php?sn=&lt;?php echo session_name(); ?&gt;&amp;sid=&lt;?php echo md5(uniqid()) ?&gt;&quot; 
                    alt=&quot;CAPTCHA Image&quot; align=&quot;left&quot;&gt;
                &lt;object type=&quot;application/x-shockwave-flash&quot; 
                    data=&quot;securimage/securimage_play.swf?bgcol=#ffffff&amp;amp;icon_file=securimage/images/audio_icon.png&amp;amp;audio_file=securimage/securimage_play.php&quot; 
                    height=&quot;32&quot; width=&quot;32&quot;&gt;
                  &lt;param name=&quot;movie&quot; 
                    value=&quot;securimage/securimage_play.swf?bgcol=#ffffff&amp;amp;icon_file=securimage/images/audio_icon.png&amp;amp;audio_file=securimage/securimage_play.php&quot; /&gt;
                &lt;/object&gt;
                &amp;nbsp;
                &lt;a tabindex=&quot;-1&quot; style=&quot;border-style: none;&quot; href=&quot;#&quot; title=&quot;Refresh Image&quot; 
                    onclick=&quot;document.getElementById(&#039;siimage&#039;).src = &#039;securimage/securimage_show_n.php?sn=&lt;?php echo session_name(); ?&gt;&amp;sid=&#039; + Math.random(); this.blur(); return false&quot;&gt;
                &lt;img src=&quot;securimage/images/refresh.png&quot; alt=&quot;Reload Image&quot; 
                    height=&quot;32&quot; width=&quot;32&quot; 
                    onclick=&quot;this.blur()&quot; align=&quot;bottom&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
                &lt;br /&gt;
                &lt;strong&gt;Enter Code*:&lt;/strong&gt;&lt;br /&gt;
                &lt;input type=&quot;text&quot; name=&quot;ct_captcha&quot; size=&quot;12&quot; maxlength=&quot;8&quot; /&gt;
            &lt;/td&gt;
&lt;?php
            end_row();
        }</code></pre></div><p>File: includes/current_user.inc<br />Insert at Line 78:<br /></p><div class="codebox"><pre><code>            if (!($this-&gt;timeout)) captchacheck();</code></pre></div><p>Append following function before last closing PHP tag:<br /></p><div class="codebox"><pre><code>function captchacheck() {
    global $use_captcha_for_login;

    if ($use_captcha_for_login) {
        // make sure that login_timeout is not affected
        if (isset($_POST[&#039;ct_captcha&#039;])) $_SESSION[&#039;ct_captcha&#039;] = $_POST[&#039;ct_captcha&#039;];
        // Check CAPTCHA
        require_once &#039;securimage/securimage.php&#039;;
        $securimage = new Securimage();

        $usrcaptcha = $_SESSION[&#039;ct_captcha&#039;];

        if ($securimage-&gt;check($usrcaptcha) == false) {
            // CAPTCHA Failed
            echo &quot;The security code entered was incorrect.&lt;br /&gt;&lt;br /&gt;&quot;;
            echo &quot;Please go &lt;a href=&#039;javascript:history.go(-1)&#039;&gt;back&lt;/a&gt; and try again.&quot;;
//            captcha session variables used - unset still cannot prevent cached image
            // unset($_SESSION[&#039;securimage_code_disp&#039;]);
            // unset($_SESSION[&#039;securimage_code_value&#039;]);
            // unset($_SESSION[&#039;securimage_code_ctime&#039;]);
            exit;
//            return false;
        } else {
            // CAPTCHA OK
            return true;
        }
    } else return true;

}</code></pre></div>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2012-09-14T15:56:34Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=13354#p13354</id>
		</entry>
</feed>
