[RFC] XML_Annotea and Authenticating Users...
| From: | Davey | Date: | Sat, 18 Oct 2003 22:11:14 +0000 |
| Subject: | [RFC] XML_Annotea and Authenticating Users... | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-22805@lists.php.net to get a copy of this message | ||
Hey,
I'd like to get some input, the Annotea spec says that a server should allow authentication using HTTP Basic Auth... now, my question is, how
should I go about this?
Do I use HTTP_Auth within the package... or leave it upto the developer
using XML_Annotea to wrap the server stuff in HTTP_Auth should they need it?
I have the choice of making XML_Annotea_Server take care of Authentication, though I need to think about how to let the user
specify how the auth is done... the idea that I have come to mind is allowing the user to pass in an object with pre-defined method name(s)
for authenticating with pre-defined return values...
class My_XML_Annotea_Auth {
function auth($user,$pass) {
// do auth stuff here
if ($authed == TRUE) {
return TRUE;
} else {
return FALSE;
}
}
/* Is there any need for other methods *needed* by XML_Annotea to auth? */} $auth_object = new My_XML_Annotea_Auth; $server = new XML_Annotea_Server($auth_object); and in XML_Annotea_Server: function XML_Annotea_Server($auth) {
$auth->auth($_SERVER['PHP_AUTH_USER'],$_SERVER['PHP_AUTH_PW']);
// existing code
}
Or some such, haven't look what Auth_HTTP needs me to do yet...
I think I'd *like* to take the "leave auth upto user" approach, keeps
XML_Annotea cleaner... but I'd like some thoughts on what you think...
- Davey