Re: another Auth-class
| From: | Jean-Michel POURE | Date: | Tue, 30 Oct 2001 07:01:39 +0000 |
| Subject: | Re: another Auth-class | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-2433@lists.php.net to get a copy of this message | ||
Hello Wolfram,
Very interesting.
Do you manage user rights, groups and profiles ? User rights should not be restricted to Read, Edit and Delete. You should be able to define any kind of right (Download, Drill-down, etc...), group users and define profiles.
Also, there should be a possibility to define rules triggered during permission checking.
It is very important to be able to display a minimal GUI for incorporation in target applications.
Best regards,
Jean-Michel POURE
At 01:40 30/10/01 +0100, you wrote:
I have written another Auth-classes based on the PEAR::DB concept (which i really like - thanks Stig) http://wolfram.kriesing.de/programming/index.php here some features/thought about it (from the README) After thinking about how to do it and finding the combination of Tomcat4 and PEAR:DB concept the best solution i started implementing it. And i am very happy with this concept (thanks Stig Bakken for PEAR::DB) it just gives me all the freedom and flexibility i need. I hope it helps you too. This class was inspired by the PEAR::DB and tomcat4 (catalina). I really like the way tomcat was enabling an always needed authentication, no matter if via DB or LDAP. And i am using the PEAR::DB already for quite a long time and i find it very useful and handy. And after evaluating the PEAR::Auth i just didnt find it really meeting all my needs. And an authentication system is also some kind of abstraction, because there might be a DB, LDAP or whatever below which stores the authentication data. WAYS TO USE THE CLASS 1. You can use this class as a normal auth-class using the methods 'login', 'logout', 'isLoggedIn', 'isExpired', ... etc. But then you always have to check the current state (logged in, logged out, error cases, etc.). 2. You can use this class in 'auto-Auth' mode, which protects all specified pages automatically. When a user wants to access a protected page and he is not logged in he will be redirected to the login-page, after successful login he will automatically be redirected to the requested page. If the login fails he will be redirected to the error-page. If the page expires he will be redirected to the expire-page. and a lot more .... interested? thoughts about it? Wolfram -- PEAR Development Mailing List (http://pear.php.net/) To unsubscribe, e-mail: pear-dev-unsubscribe@lists.php.net For additional commands, e-mail: pear-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net