Re: LDAP_SCOPE_SUBTREE
| From: | Ignacio Vazquez-Abrams | Date: | Sun, 26 Nov 2000 05:37:18 +0000 |
| Subject: | Re: LDAP_SCOPE_SUBTREE | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-27238@lists.php.net to get a copy of this message | ||
On Sun, 26 Nov 2000, Corisen wrote:
> thank you so much. ldap_list() is exactly what i'm looking for.
>
> would appreciate if you could spend some time to share your experience
> & knowledge on the following questions regarding ldap.
I don't have a heck of a lot of experience with LDAP, but I'll try and help
nonetheless :)
> i'll be using php to desig a web-based registration. there will be a
> drop down list on this web-based form to select the user's department. i've
> thought of 2
> ways of dynamically populating the department drop-down list:
>
> Method 1. design the ldap name space to contain department name and limit
> the ldap
> query to one level (from root: dc=mycompany, dc=com) to retrieve all the
> departments:
> i.e. uid=username, o=departmentname, dc=mycompany, dc=com
>
> Method 2. store the department name in a mysql database and dynamically
> populate
> the drop-down list by querying mysql.
>
> my worries about method 1 is whether the php API can perform the following
> tasks:
> 1. if the department changes name, how can i update the dn of all the users
> under this department tree?
You would probably have to prune and graft the department.
> 2. if a user change department, how can i update his dn to uid=username,
> o=newdept, dc=mycompany, dc=com?
You would probably have to prune and then graft the user.
> 3. how can i delete a department and all the entries under it's tree?
You would have to delete all the subnodes one by one starting from the bottom.
> 4. is including the o=department in the dn a good design? or should i just
> use "uid=username, dc=mycompany,dc=com"?
It depends on whether or not having the departments as seperate trees in the
directory makes any sense (usually yes).
> 5. what are the pros and cons of using "o" in the dn?
Well, longer DNs for one. More complicated/flexible structure.
> using method 2, the name space design is simpler: uid=username,
> dc=mycompany, dc=com. but i have to keep duplicate/two sets of department
> records. one in mysql and one in ldap. and they must be synchronise when any
> department is modified, deleted or added.
>
> i really have no idea what might be the complications for each method and
> which is a better way of designing. ldap will also be used of authentication
> other than storing the department name.
>
> thank you so much.
>
--
Ignacio Vazquez-Abrams <ignacio@openservices.net>