Re: [patch] Auth to have case sensitive username matching in DB container
| From: | Yavor Shahpasov | Date: | Tue, 18 May 2004 14:45:18 +0000 |
| Subject: | Re: [patch] Auth to have case sensitive username matching in DB container | ||
| References: | 1 2 3 4 5 6 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-29353@lists.php.net to get a copy of this message | ||
Hello Walter,
if your patch is to be rejected by any one it would be up to me to do it. it would be nice if in future you would post a diff instead of code with comments, it is easier to follow i guess.
I took over maintenance of auth some time ago, I assume that the change password feature was rejected by martin. I too agree that user managment should be left
out of auth but since the add / remove user methods are there already i desided to stretch the line just a bit more.
I believe the only correct way to solve this is to force the username to be in a certain case (upper or lower).
Checking if the return value is the same as the requested value is for me wrong and should be handled by the database. If there is any
misrepresentation of information it comes from the database. For example you tell the database give me user 'Joe' but instead you get
user 'jOe'. That is the detabase fault and should be taken care there.
The best solution you have is writing a custom auth container, it is only a few lines of code.
As always everything is open for discussion but for now your patch is not accepted.
Yavor
[php]Walter wrote:
"Michael Wallner" <mike@php.net> wrote in message news:20040513210249.4459.qmail@pb1.pair.com...-- Yavor Shahpasov yavo@siava.org Linux is not The Answer. Yes is the answer. Linux is The Question.I'm against adding this bloat to Auth because of a simple reason, whichis,that YOU can decide if Auth is case-sensitiveSo, it looks like this is the final word on the subject. The "patch" is rejected.or not by administering your database in a smart and concious way.that OK for people who have control over their DB. But it leaves the other out in the cold. It forces them to create workarounds, thus (in my view) defeating the underlaying purpose of PEAR: "Simplify your life" Oh well. Walter BTW: What I find very interesting is that last year I asked about adding"change password" to the class and was informed that this "feature" is outside the sphere of what Auth does: Authentication, not user management. After some reflection, I came to agree. Now I see that this "feature" has been added under the suggestion of someone else. I sure would like to know what his arguements where to convice the powers that be to add "changePassword".