RE: [PEAR-DEV] New Package Proposal: Enterprise A&A
| From: | Tony Bibbs | Date: | Tue, 14 Jan 2003 22:04:53 +0000 |
| Subject: | RE: [PEAR-DEV] New Package Proposal: Enterprise A&A | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-12440@lists.php.net to get a copy of this message | ||
You can pass rights around in bulk by using groups. Remember, groups can
have permissions tied to them as well as users. Thus if you have a
module, foo, that you want to group rights with, create a group called
Foo-user and then assign rights to them. I still don't see the value of
managing the implication that one right has on another....that is a lot of
overhead IMHO. As a web service handling a lot of requests I'd even argue
this overhead would show significant performance issues. Just get the
rights, give em back the app and have a nice day ;-)
Good discussion!
--Tony
On Tue, 14 Jan 2003,
Lukas Smith wrote:
> > -----Original Message-----
> > From: Tony Bibbs [mailto:tony@tonybibbs.com]
> > Sent: Tuesday, January 14, 2003 9:25 PM
> > To: Lukas Smith
> > Cc: 'Roberto Bertó'; 'PEAR Development'
> > Subject: RE: [PEAR-DEV] New Package Proposal: Enterprise A&A
> >
> > Yeah I saw live user. There are some similar concepts and you have
> the
> > benefit of at least a couple of additional heads. I didn't see a
> > convenient link to CVS for it on the PEAR site so without seeing some
> of
> > the code, it doesn't sound like it was designed to be exposed as a web
> > service. Is that right?
>
> Actually it is planned to have an xml-rpc/soap interface.
>
> > Regarding implied rights, the A&A system makes no assumptions about
> how
> > permissions are used. It is up to the application to design
> appriopriate
> > permissions as needed. That, IMHO, offers the greatest level of
> > flexibility. All I do is get the groups a user belongs to any rights
> > those groups may have and any rights tied directly to the user. How
> those
> > rights are used is up to the application.
>
> Of course this can be handled on the application level. But this is a
> common requirement. I for one want to group rights for all my modules
> because I also want to be able to define special types users that have
> all rights to one module etc. Implied rights are just a handy tool to
> ensure that users get all the rights they need. Using implied rights you
> can also bundle several rights to be easily granted or revoked.
>
> > So, now what?
>
> Be a little more patient :-)
> I have not looked at the source myself nor am I currently an active
> contributor to LiveUser. Anyways I am sure the active contributors to
> LiveUser will take a look at your package and so will other pear users.
> As this is not a simple package it will take people a bit longer to
> comment.
>
> Regards,
> Lukas
>
>
>
--
------------------------------------------------------------------------|
Tony Bibbs | "I guess you have to remember that those who don't |
tony@tonybibbs.com | hunt or fish often see those of us who do as |
| harmlessly strange and sort of amusing. When you |
| think about it, that might be a fair assessment." |
| --Unknown |
------------------------------------------------------------------------|