[RFC] XML_Annotea and Authenticating Users...

From: Date: Sat, 18 Oct 2003 22:11:14 +0000
Subject: [RFC] XML_Annotea and Authenticating Users...
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-22805@lists.php.net to get a copy of this message
Hey, I'd like to get some input, the Annotea spec says that a server should allow authentication using HTTP Basic Auth... now, my question is, how should I go about this? Do I use HTTP_Auth within the package... or leave it upto the developer using XML_Annotea to wrap the server stuff in HTTP_Auth should they need it? I have the choice of making XML_Annotea_Server take care of Authentication, though I need to think about how to let the user specify how the auth is done... the idea that I have come to mind is allowing the user to pass in an object with pre-defined method name(s) for authenticating with pre-defined return values... class My_XML_Annotea_Auth {
    function auth($user,$pass) {
        // do auth stuff here
        if ($authed == TRUE) {
            return TRUE;
        } else {
            return FALSE;
        }
    }
    /* Is there any need for other methods *needed* by XML_Annotea to auth? */
} $auth_object = new My_XML_Annotea_Auth; $server = new XML_Annotea_Server($auth_object); and in XML_Annotea_Server: function XML_Annotea_Server($auth) {
    $auth->auth($_SERVER['PHP_AUTH_USER'],$_SERVER['PHP_AUTH_PW']);
    // existing code
} Or some such, haven't look what Auth_HTTP needs me to do yet... I think I'd *like* to take the "leave auth upto user" approach, keeps XML_Annotea cleaner... but I'd like some thoughts on what you think... - Davey

« previous php.pear.dev (#22805) next »