5 ms·
I'm just coming up with this off the top of my head, but: 1. When loading the survey page check for a cookie. If it's not present, set the cookie, record the
by arantius 18y ago
I'm just coming up with this off the top of my head, but:
1. When loading the survey page check for a cookie. If it's not present, set the cookie, record the ip-and-cookie mapping, and redirect back to this page.
2. Now that we're loading the page with the cookie, present the form.
3. Upon submission of the form, validate that this IP was previously assigned this cookie, record the ip-cookie-vote triplet. Throw out the vote if that IP hasn't been assigned that cookie.
If a scripter wants to automate requests, they'll have to figure out that they need to get the cookie from you, then use it to vote. You can detect abnormally large ip-vote (and timeframe) combinations and automatically, or later manually, discard anomalous results.
It's not perfect of course, but there is no such thing as a perfect internet survey (unless you're going to mail out SeucurID fobs or some such to the participants).