Re: [patch] Auth to have case sensitive username matching in DB container
| From: | \[php\]Walter | Date: | Thu, 13 May 2004 20:32:20 +0000 |
| Subject: | Re: [patch] Auth to have case sensitive username matching in DB container | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-29220@lists.php.net to get a copy of this message | ||
"Yavor Shahpasov" <yavo@siava.org> wrote in message
news:40A3266A.6070005@siava.org...
> In the light of the below discussion, i think there should be an option
> which makes sure that the user name is sent to the database in a
> single case
>
> ex
> $auth->setUsernameCase(UPPER|LOWER)
I'm not all that sure of this solution.
Is this concept to be used instead of setCaseCheck()?
On one hand, the DB may or may not handle case-sensitivity.
Currently, Auth simple queries the DB with a given username, case untouched.
The DB will return a record or not. If the DB is case-sensitive, and the
case does not match, the DB returns nothing. If the DB is case-insensitive,
then the DB returns a record (assuming it found a match).
This is all Auth uses to determine the existence of the given user.
The patch I gave does a second level check.
If the DB returns a record, Auth checks case matching. This works if the DB
does case matching or not. Thus Auth handles the NOT FOUND based upon case.
If the DB does case matching, and the DB does not return a record because of
case, then the DB handled the NOT FOUND based upon case.
Either way, case matching is handled, if desired $auth->setCaseCheck(T|F)
Now, what my patch does not address is the situation where the developer set
setCaseCheck to F, but the DB does case matching. In that instance your
setUsernameCase is needed, simply to insure that the developer is getting
what he is expecting, regardless of what the DB does.
So, this then begs the next question: should the CASE be determined by a SET
method of should it just be "taken care of" by Auth itself?
Right now, taking both concepts into consideration...
If I want a case-sensitive user name check...
$auth->setCaseCheck(T)
OK, now Auth will do the checking, regardless of what the DB does.
But, what if the it is set to F *and* the DB does case matching, then
setUsernameCase needs to be used to insure desired/expected results.
So this issue has to be addressed on both sides here, checking and adding
username.
If setCaseCheck = F, than setUsernameCase needs to be used to insure results
regardless of DB operations. This side-steps case matching DBs.
If setCaseCheck = T, than setUsernameCase can not be used to insure results
regardless of DB operations. This ignores case matching DBs.
Or am I way off base on this?
Walter