Re: another Auth-class
| From: | Wolfram Kriesing | Date: | Tue, 30 Oct 2001 16:47:35 +0000 |
| Subject: | Re: another Auth-class | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-2455@lists.php.net to get a copy of this message | ||
> PEAR::Auth already uses storage containers. Currently there is only
> an interface to PEAR::DB available, but others are easy to
> implement.
may be the best things of each can simply be used to end up with the
very best!
When i was searching for an existing Auth class i also came across
the one in PEAR. The problem was i was spoiled by what Tomcat
provided and it also seemed strange to me that the abstraction of the
data source, you authorize against (DB or whatever) was done in a
different way than PEAR::DB. I think PEAR::DB is a concept that
rocks. Any reasons for not implementing this in your Auth-class?
I was also missing the simple methods login, logout ... i got a bit
confused by setAuth, getAuth ...
And providing an Auth-system which doesnt bother you with that stuff
anymore, which simply does the job was what i was looking for.
So i implemented this auto-auth mode.
Example:
---------------------------
require("Auth.php");
$options = array( 'protectRoot'=>'',
'protect'=> array(
'/applDir',
'/applDir1',
'/appl2/secret.php'
)
);
$auth = Auth::setup( 'DB:mysql://user@host/db' , $options );
---------------------------
and the authentication is taken care of
- if you simply include a (config-)file that has that code inside,
the authentication is done automatically if needed
- all directories/files given in the option 'protect' require
authentication
- no isLoggedIn()-check needs to be done anywhere, since the class
takes care of all this
sure you can also use the class without this 'autoauth'
it provides:
login(), logout(), isLoggedIn(), isExpired() ...
but then you have to handle the redirecting to the login-page and all
this stuff by hand
try it ...
I just woke up one night knocking my head on the bed side table and
asking myself why i hadnt come up with the idea, of implementing the
PEAR::DB concepts in the Auth classes, before.
--
Wolfram