ramifications of propsed change to Auth/Auth.php
| From: | jsWalter | Date: | Mon, 01 Sep 2003 20:00:17 +0000 |
| Subject: | ramifications of propsed change to Auth/Auth.php | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-20972@lists.php.net to get a copy of this message | ||
(I guess backward compatibility is an issue here as well)
I would like to propose that Auth::Auth.php auth class definition have no
required parameters.
Since it currently only needs to have 'storageDriver' type defined, I
propose that it default to 'DB', since that type does not have any required
parameters.
I made the change in my copy, and now I am validating pages using...
$a = new Auth();
so I can do validation of session without having to define DRIVER type.
Why?
I figured, since driver type parameters are optional why not driver type as
well. Looking deeper into the methods, I saw that loads storage classes are
based upon this definition. My first thought was to have the '_factory'
method just bale out if no type is defined, but I thought that might break
something I'm not seeing, so, I figured just default to 'DB'.
<But then I had second thoughts on that and now I'm asking those wiser than
I.>
I really feel that all parameters to auth() should be optional, since AFAIK
(or can see) they are not used beyond the initial authorization or new user
DB (or whatever driver type) access.
I made this change in Auth::Auth.php
function _factory($driver = 'DB', $options = "")
This sets the default "driver" type to DB.
Then I was thinking that it might be better to have the default setting for
driver type to the actual AUTH class call...
function Auth($storageDriver = 'DB', $options = "", $loginFunction =
"", $showLogin = true)
This will leave _factory alone so it will work as created when other methods
use it.
Then I noticed that if "I" do that and I want to have an auto-login at an
error point ($showLogin = true), and all the others are optional, this call
would not be pretty...
$a = new auth(null, null, null, true)
So, then make '$showLogin = true' the first parameter (which breaks all code
previous!). Then I can really have a simplified authentication call...
$a = new auth() /* is user authenticated? No login if not */
or
$a = new auth(true) /* is user authenticated? Show login if not */
Can anyone see the ramifications of this, beyond BC issues?
Will this come bit me in the butt later?
Or am I missing something really obvious here.
Thanks
Walter