Link to home
Start Free TrialLog in
Avatar of pinkstonm
pinkstonm

asked on

Forcing and ID into the guestbook

I have a simple guestbook uses a post.htm a gbook.gbt and a gbook.htm file.  How can I force it so that when a user fills out the guestbook that their email id automatically is trapped?

Thanks
Avatar of avner
avner

You cannot do that !

It'll be a security hole if you'll be able to do such thing.
You can't. If they don't want to give it, you can't get it.
Fortunately the browser does not even know the users email address.  The o/s doesn't even know it.  The only sofware on the client that would be aware of an email address is the email client, if the user had it configured.

I have about 30 different email address that I use to manage my filing.  Which one would you want to grab?

You want to be cautious with this kind of an approach to web page design.  On the intranets that I am responsible for, if we detect a page trying to take without permission it gets classified as hostile and we block the site at the firewall.

That prevents anyone on the local network from accessing the site.  The largest of those networks has 80,000 users that would no longer be able to go to the site.

That kind of policy is not unique.  Most intranet security systems will block you completely if you try to access anything on the client.

There is a simple solution.  Ask the user for their email address.

Cd&
Cd said it! Ask the user for their email address. If they want you to have it they will give it to you,
times 4.
Avatar of pinkstonm

ASKER

that stinks.  People can put in nasty stuff and you can't respond
On most guest books I have seen you can set them such that you can see any thing they post, and must approve it before it becomes public. You may not be able to email someone for saying nasty stuff, but you can delete it so that no one but you sees it.
Oh, I understand the problem you've got  now.  It is one ever site that allows thing to be posted has.  You could require that they enter and email address to post, but they could give you any address.

They have the same problem on this site.  CS has to remove profanity and other inappropriate posts all the time.  They have an email address but, all that lets them do is let the individual know that their account has been closed.

The population of web users has a small percentage of idiots who hide behind aliases and think it fun to urinate on the rest of the world. Responding to them probably just satisfies their need for some attention in their pathetic lives.

IMHO

Cd&
ASKER CERTIFIED SOLUTION
Avatar of webwoman
webwoman

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
And some of them even avoid displaying new entries until the webmaster processes them using an easy interface.
Is there still more to do here?

Cd&