To add CAPTCHA to forms in Yii, first enable the CAPTCHA action in your controller by defining it in the actions() method, which creates a dynamic route for generating the CAPTCHA image. Second, create a verifyCode attribute in your form model and apply the captcha validation rule to it. Third, display the CAPTCHA in your form view using the Captcha widget with a custom template and correct captchaAction path. Finally, during form submission, Yii automatically validates the CAPTCHA input as long as the model’s validate() method is called, ensuring the entered code matches the generated one. Common issues include incorrect session setup or caching pages with CAPTCHA, which should be avoided.
Adding CAPTCHA to forms in Yii is a straightforward way to prevent bots from submitting your forms. It involves setting up both the front-end display and the back-end validation, and Yii provides built-in support for this.
1. Enable CAPTCHA in Your Controller
Before displaying the CAPTCHA on a form, you need to configure it in your controller. This is done by declaring a captcha
action in the controller where your form is being handled.
public function actions() { return [ 'captcha' => [ 'class' => 'yii\captcha\CaptchaAction', 'fixedVerifyCode' => YII_ENV_TEST ? 'testme' : null, ], ]; }
This sets up a route like /your-controller/captcha
that will generate the CAPTCHA image dynamically. The fixedVerifyCode
line helps during testing so you can bypass manual CAPTCHA entry.
2. Add CAPTCHA Field to Your Form Model
You’ll need to create a field in your model (usually a form model) to hold the user’s CAPTCHA input. This field should be validated using the captcha
validator.
public $verifyCode; public function rules() { return [ // other rules... ['verifyCode', 'captcha'], ]; }
Make sure your model extends yii\base\Model
or one of its subclasses.
3. Display CAPTCHA in the Form View
In your view file, use the Captcha
widget to render the CAPTCHA image and input field.
<?= $form->field($model, 'verifyCode')->widget(yii\captcha\Captcha::className(), [ 'captchaAction' => '/controller/captcha', 'template' => '<div class="row"><div class="col-lg-3">{image}</div><div class="col-lg-6">{input}</div></div>', ]) ?>
Here:
-
captchaAction
points to the CAPTCHA action you set up earlier. -
template
allows you to customize how the CAPTCHA image and input box are displayed together.
Tip: If you're using Bootstrap, wrapping them in grid columns like shown above keeps the layout clean.
4. Handle Validation During Form Submission
When the form is submitted, the captcha
rule in your model ensures the entered code matches the generated one. If not, an error message will automatically appear next to the CAPTCHA field.
No extra code is needed in your controller action that handles the form submission — just make sure you call $model->validate()
or let Yii handle it via ActiveForm.
Some Common Issues to Watch For
- CAPTCHA not showing: Make sure the captcha action is properly defined in the controller.
- Validation always fails: Double-check that the session component is working — CAPTCHA relies on sessions to store the correct code.
- Caching issues: If you're using page caching, avoid caching pages with CAPTCHA since each CAPTCHA must be unique per session.
That's basically it. It doesn’t require much setup, but it adds a solid layer of protection against spam and bot submissions.
The above is the detailed content of How do I use CAPTCHA in Yii forms?. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

YiiassetbundlesorganizeandmanagewebassetslikeCSS,JavaScript,andimagesinaYiiapplication.1.Theysimplifydependencymanagement,ensuringcorrectloadorder.2.Theypreventduplicateassetinclusion.3.Theyenableenvironment-specifichandlingsuchasminification.4.Theyp

In the MVC framework, the mechanism for the controller to render views is based on the naming convention and allows explicit overwriting. If redirection is not explicitly indicated, the controller will automatically find a view file with the same name as the action for rendering. 1. Make sure that the view file exists and is named correctly. For example, the view path corresponding to the action show of the controller PostsController should be views/posts/show.html.erb or Views/Posts/Show.cshtml; 2. Use explicit rendering to specify different templates, such as render'custom_template' in Rails and view('posts.custom_template') in Laravel

When saving data to the database in the Yii framework, it is mainly implemented through the ActiveRecord model. 1. Creating a new record requires instantiation of the model, loading the data and verifying it before saving; 2. Updating the record requires querying the existing data before assignment; 3. When using the load() method for batch assignment, security attributes must be marked in rules(); 4. When saving associated data, transactions should be used to ensure consistency. The specific steps include: instantiating the model and filling the data with load(), calling validate() verification, and finally performing save() persistence; when updating, first obtaining records and then assigning values; when sensitive fields are involved, massassignment should be restricted; when saving the associated model, beginTran should be combined

The method of creating custom operations in Yii is to define a common method starting with an action in the controller, optionally accept parameters; then process data, render views, or return JSON as needed; and finally ensure security through access control. The specific steps include: 1. Create a method prefixed with action; 2. Set the method to public; 3. Can receive URL parameters; 4. Process data such as querying the model, processing POST requests, redirecting, etc.; 5. Use AccessControl or manually checking permissions to restrict access. For example, actionProfile($id) can be accessed via /site/profile?id=123 and renders the user profile page. The best practice is

TocreateabasicrouteinYii,firstsetupacontrollerbyplacingitinthecontrollersdirectorywithpropernamingandclassdefinitionextendingyii\web\Controller.1)Createanactionwithinthecontrollerbydefiningapublicmethodstartingwith"action".2)ConfigureURLstr

AYiidevelopercraftswebapplicationsusingtheYiiframework,requiringskillsinPHP,Yii-specificknowledge,andwebdevelopmentlifecyclemanagement.Keyresponsibilitiesinclude:1)Writingefficientcodetooptimizeperformance,2)Prioritizingsecuritytoprotectapplications,

TouseActiveRecordinYiieffectively,youcreateamodelclassforeachtableandinteractwiththedatabaseusingobject-orientedmethods.First,defineamodelclassextendingyii\db\ActiveRecordandspecifythecorrespondingtablenameviatableName().Youcangeneratemodelsautomatic

AYiideveloper'skeyresponsibilitiesincludedesigningandimplementingfeatures,ensuringapplicationsecurity,andoptimizingperformance.QualificationsneededareastronggraspofPHP,experiencewithfront-endtechnologies,databasemanagementskills,andproblem-solvingabi
