Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest
| From: | Martin Jansen | Date: | Thu, 04 Mar 2004 08:02:20 +0000 |
| Subject: | Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-26085@lists.php.net to get a copy of this message | ||
On Thu Mar 04, 2004 at 07:3600AM +0900, Rui Hirokawa wrote:
> On Wed, 3 Mar 2004 08:13:23 +0100 Martin Jansen <mj@php.net> wrote:
> > - I really do not like the fact that the database is accessed directly
> > in login(). Isn't there an easy way to handle this inside the storage
> > containers?
>
> I tried to implement login() in more generic way, but I failed.
>
> It is because authentication like
>
> md5('password from user'+'temporal parameter1 ') ==
> md5('password from container'+'temporal parameter2 ')
>
> is not supported in the current implementation.
> It is necessary to implement the digest authentication.
Sounds reasonable. I also do not think that all parts of the
implementation have to perfect in the first release. (We might roll a
_beta_ release of Auth_HTTP that includes digest authentication and then
see how things turn out.)
> I think we should add a method like getPassword() into Auth() to
> retrieve password from container.
> I also recommend to move the authentication part from containers class
> to Auth() class for clarification.
You should discuss that with Yavor.
--
- Martin Martin Jansen
http://martinjansen.com/