Re: New Package Proposal: Enterprise A&A
| From: | Tony Bibbs | Date: | Tue, 14 Jan 2003 22:10:01 +0000 |
| Subject: | Re: New Package Proposal: Enterprise A&A | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-12441@lists.php.net to get a copy of this message | ||
I won't rule that out. And I to be clear, I read the PEAR descriptor on
LiveUser. It may aim at the same tasks, I agree there, but the *big*
differences are a) web service-based and b) architected to support single
sign-on. Again, I have a big picture in mind which is to support the
liberty project's interfaces which can be done minimal work with what we
I have. Don't read this wrong, I'm taking it a tad personal just because
I wrote it but if you have a plan for how these two might be merged I'd
like to hear them.
The guts of it (authentication/authorization) are trivial IMHO. The real
value is having it as a service and on a platform that can meet Enterprise
needs.
--Tony
On Tue, 14 Jan 2003, Markus Wolff wrote:
> On Tue, 14 Jan 2003 12:37:29 -0600 (CST)
> Tony Bibbs <tony@tonybibbs.com> wrote:
>
> > I have a package still in alpha but has most of the key components
> > working. It is aimed to be an Enterprise Authentication & Authorization
> > service. The key features are:
> >
> > 1) XML-RPC based (future version moved to SOAP/WSDL)
> > 2) Implements a single-credential set across multiple applications
> > 3) Extendable. This library uses the concept of a provider. By default
> > it will ship with a SQL Provider (using PEAR::DB) and can be easily
> > adapted for LDAP or any custom needs. (I could use help with LDAP if there
> > are any takers)
> > 4) 100% OO, PHP client will return a serializable user object that holds
> > all authorization data for a user.
> > 5) Extensive logging. Troubleshooting can be a pain when the client and
> > server are separated. This is alleviated a bit using PEAR::Log
>
> Hi Tony,
>
> from the end of your mail I can see that you didn´t take a look at
> LiveUser. Basically this package does pretty much exactly what your
> package seems to do, but it doesn´t have an XML-RPC driver/provider yet
> (only one authentication driver based on PEAR::DB and two authorisation
> drivers, both also based on PEAR::DB, but implementing different feature
> sets).
>
> The concepts sound identical - maybe the two packages can benefit from
> each other?
>
> Regards,
> Markus
>
>
--
------------------------------------------------------------------------|
Tony Bibbs | "I guess you have to remember that those who don't |
tony@tonybibbs.com | hunt or fish often see those of us who do as |
| harmlessly strange and sort of amusing. When you |
| think about it, that might be a fair assessment." |
| --Unknown |
------------------------------------------------------------------------|