Re: New Package Proposal: Enterprise A&A
| From: | Tony Bibbs | Date: | Tue, 14 Jan 2003 19:28:08 +0000 |
| Subject: | Re: New Package Proposal: Enterprise A&A | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-12427@lists.php.net to get a copy of this message | ||
Like I said, I have a mostly working version of it. I need to do a few
CVS updates to have CVS working. In the meantime you can peep it here:
http://cvs.geeklog.net/chora/cvs.php/A_and_A?login=2&Horde=94843094d509d53f118717c247cefa3d
Here is an authentication sample:
$user = &AAServiceInterface::authenticate($_CONF['AA_server'],
$_CONF['AA_server_path'], $_CONF['AA_appId'], $_POST['username'],
$_POST['password'], $_CONF['AA_port']);
The code is pretty well structured but still could use some approvements.
This task is a huge one so I could use at least one other head on it to
help get it stable...assuming it gets approved.
Authorization model is heirarchical. Groups are supported. Nested groups
are supported too. Privileges can be tied to groups or individuals.
FYI you *can* use this for just authentication if you want. A good
example of that would be integrating two apps which manage their own user
data and permissions. If you wanted a single credential set you simply
swap out their authentication with calls to this A&A service. Obviously
some customizations would be needed on account creation but it's not that
bad.
--Tony
On 14 Jan 2003, Roberto Bertó wrote:
> I liked its descriptions. How do will work the authorization system? It
> have an hierarchy? How does it works?
>
> I guess you should take a look on the PEAR classes to see if it's
> possible to add your work on them.
>
> But, like MDB and DB, if the things isn't compatible, I guess its really
> possible have your class approved.
>
>
>
>
>
> On Tue, 2003-01-14 at 15:37, Tony Bibbs wrote:
> > I have a package still in alpha but has most of the key components
> > working. It is aimed to be an Enterprise Authentication & Authorization
> > service. The key features are:
> >
> > 1) XML-RPC based (future version moved to SOAP/WSDL)
> > 2) Implements a single-credential set across multiple applications
> > 3) Extendable. This library uses the concept of a provider. By default
> > it will ship with a SQL Provider (using PEAR::DB) and can be easily
> > adapted for LDAP or any custom needs. (I could use help with LDAP if there
> > are any takers)
> > 4) 100% OO, PHP client will return a serializable user object that holds
> > all authorization data for a user.
> > 5) Extensive logging. Troubleshooting can be a pain when the client and
> > server are separated. This is alleviated a bit using PEAR::Log
> >
> > The end state of this will be allowing for single sign-on. I hope to do
> > this by integrating all this with the liberty project.
> >
> > I know you already have a few A&A-based packages, admittedly I haven't
> > looked at any of them. My hunch is this is the first one that aims to be
> > true web service and plans to support single sign-on.
> >
> > --
> > ------------------------------------------------------------------------|
> > Tony Bibbs | "I guess you have to remember that those who don't |
> > tony@tonybibbs.com | hunt or fish often see those of us who do as |
> > | harmlessly strange and sort of amusing. When you |
> > | think about it, that might be a fair assessment." |
> > | --Unknown |
> > ------------------------------------------------------------------------|
>
--
------------------------------------------------------------------------|
Tony Bibbs | "I guess you have to remember that those who don't |
tony@tonybibbs.com | hunt or fish often see those of us who do as |
| harmlessly strange and sort of amusing. When you |
| think about it, that might be a fair assessment." |
| --Unknown |
------------------------------------------------------------------------|