RE: [PEAR-DEV] New Package Proposal: Enterprise A&A
| From: | Tony Bibbs | Date: | Wed, 15 Jan 2003 18:53:23 +0000 |
| Subject: | RE: [PEAR-DEV] New Package Proposal: Enterprise A&A | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-12497@lists.php.net to get a copy of this message | ||
On Wed, 15 Jan 2003, Lukas Smith wrote:
> Hi,
>
> ok the way I see it both A&A and LiveUser aim to provide the same goals
> and are somewhere in alpha and beta stage.
>
> For the most part the approach is the same (container/provider approach
> to allow different backends), but there are some structural differences.
> The backends that are supported atm are not the same however. I don't
> know if there is a language barrier or a communication barrier, because
> Tony seems to dispute this fact a lot.
Sorry, I don't dispute they aim to solve the same problem (A&A). I don't
even dispute the fact there are structural difference...after all both
were developed without the knowledge of the other. I've only harped on
the two differentiators that if you compare my original post in this
thread to what is shown in the PEAR descriptor for LiveUSer which are a)
web-service based and b) designed from scratch to eventually support the
Liberty project. After hearing more about LiveUser, it seems that b) is
possible though it was never articulated as a goal. Also a) is possible
with LiveUser. Is that accurate?
>
> When I said that I think it is wacked to have two single sign on classes
> in PEAR I say this because I think it would make sense to through as
> much weight as possible behind one single sign on system. Even though it
> is possible to make the to work with each other it is less than ideal
> and does not make the choice easier for the enterprise folks :-)
If these aren't merged I don't see a real need for one having a container
in one to support the other. If someone else creates one to suit that
purpose, great, but this should really be a 'this or that' or 'coke vs
pepsi' decision. If they are merged, great.
Also, some further discussion on permission management needs to be done
since both handle them differently. Which reminds me, I had asked for a
use case or two around permission management that may 'break' either or
both approaches...still waiting on that.
>
> To conclude:
> I would suggest deciding on one of them and merging whatever additional
> features or useful concepts the other has into it.
>
> So my question to Tony is: Is this a sensible course of action for you?
> Will you leave the code out in the open even if A&A is not chosen?
Again, I'd be open to the discussion. I have to have a system that does
this. What I have built was the result of having built a requirements
document, developing uses cases and establishing a design that would work
(I'd be happy to share these docs). Furthermore this set of documentation
was agreed upon by other project members (remember, this all started
because we had a need for this). If after analyzing Live User to see how
it meets those requirements and granted that any areas of concern can be
addressed, I have no problem merging with Live User. I'm assuming you'd
feel the same in that you'd feel comfortable merging into A&A if it meets
your needs.
We should first compare the requirements both systems and analyze them
against both system before we assume that the migration will be
A&A->LiveUser as opposed to LiveUser->A&A. I just want to give this the
due diligence it deserves. I can honestly say I'd be willing to move my
code into LiveUser granted that migration path makes the most sense.
>
> For LiveUser: The code is already in the open. The question is if the
> current developers are willing to switch if A&A is chosen. I for one
> haven't started using LiveUser in production. If I understand Markuses
> situation correctly he is the original author of LiveUser but uses an
> older version in production that is incompatible with the PEAR version
> anyways. Arnaud seems to be the person closest to using PEAR::LiveUser
> in production.
>
> I hope to find some time to look at the A&A source tonight and will then
> voice my vote.
I need to do the same for LiveUser. However, I think comparing
requirements (if you have them) would be a better starting point.
>
> Regards,
> Lukas
>
--
------------------------------------------------------------------------|
Tony Bibbs | "I guess you have to remember that those who don't |
tony@tonybibbs.com | hunt or fish often see those of us who do as |
| harmlessly strange and sort of amusing. When you |
| think about it, that might be a fair assessment." |
| --Unknown |
------------------------------------------------------------------------|