Re: New Package Proposal: Enterprise A&A

From: Date: Tue, 14 Jan 2003 19:28:08 +0000
Subject: Re: New Package Proposal: Enterprise A&A
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-12427@lists.php.net to get a copy of this message
Like I said, I have a mostly working version of it. I need to do a few CVS updates to have CVS working. In the meantime you can peep it here: http://cvs.geeklog.net/chora/cvs.php/A_and_A?login=2&Horde=94843094d509d53f118717c247cefa3d Here is an authentication sample: $user = &AAServiceInterface::authenticate($_CONF['AA_server'], $_CONF['AA_server_path'], $_CONF['AA_appId'], $_POST['username'], $_POST['password'], $_CONF['AA_port']); The code is pretty well structured but still could use some approvements. This task is a huge one so I could use at least one other head on it to help get it stable...assuming it gets approved. Authorization model is heirarchical. Groups are supported. Nested groups are supported too. Privileges can be tied to groups or individuals. FYI you *can* use this for just authentication if you want. A good example of that would be integrating two apps which manage their own user data and permissions. If you wanted a single credential set you simply swap out their authentication with calls to this A&A service. Obviously some customizations would be needed on account creation but it's not that bad. --Tony On 14 Jan 2003, Roberto Bertó wrote: > I liked its descriptions. How do will work the authorization system? It > have an hierarchy? How does it works? > > I guess you should take a look on the PEAR classes to see if it's > possible to add your work on them. > > But, like MDB and DB, if the things isn't compatible, I guess its really > possible have your class approved. > > > > > > On Tue, 2003-01-14 at 15:37, Tony Bibbs wrote: > > I have a package still in alpha but has most of the key components > > working. It is aimed to be an Enterprise Authentication & Authorization > > service. The key features are: > > > > 1) XML-RPC based (future version moved to SOAP/WSDL) > > 2) Implements a single-credential set across multiple applications > > 3) Extendable. This library uses the concept of a provider. By default > > it will ship with a SQL Provider (using PEAR::DB) and can be easily > > adapted for LDAP or any custom needs. (I could use help with LDAP if there > > are any takers) > > 4) 100% OO, PHP client will return a serializable user object that holds > > all authorization data for a user. > > 5) Extensive logging. Troubleshooting can be a pain when the client and > > server are separated. This is alleviated a bit using PEAR::Log > > > > The end state of this will be allowing for single sign-on. I hope to do > > this by integrating all this with the liberty project. > > > > I know you already have a few A&A-based packages, admittedly I haven't > > looked at any of them. My hunch is this is the first one that aims to be > > true web service and plans to support single sign-on. > > > > -- > > ------------------------------------------------------------------------| > > Tony Bibbs | "I guess you have to remember that those who don't | > > tony@tonybibbs.com | hunt or fish often see those of us who do as | > > | harmlessly strange and sort of amusing. When you | > > | think about it, that might be a fair assessment." | > > | --Unknown | > > ------------------------------------------------------------------------| > -- ------------------------------------------------------------------------| Tony Bibbs | "I guess you have to remember that those who don't | tony@tonybibbs.com | hunt or fish often see those of us who do as | | harmlessly strange and sort of amusing. When you | | think about it, that might be a fair assessment." | | --Unknown | ------------------------------------------------------------------------|

« previous php.pear.dev (#12427) next »