Comments regarding LDAP container for Auth package (version 1.2.3 Stable).

From: Date: Sat, 31 Jul 2004 03:11:55 +0000
Subject: Comments regarding LDAP container for Auth package (version 1.2.3 Stable).
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-32360@lists.php.net to get a copy of this message
I have used the Auth package to perform authentication against an Ms Active Directory server (version 1.2.3 Stable) within an enterprise web application. I think that the implementation of the LDAP container is very good, however I have several additions/comments about it: Since my application supports multiple authentication methods, that can be used interchangeably, I have determined that it is not possible for me to use the Auth package in the way it is described in the End-User documentation, i.e.: $a = new Auth("LDAP", $params, "custom_function"); $a->start(); Hence I basically made a hack and used it in the following way: ----> START require("Auth/Container/LDAP.php"); $params = array(
	'host'      => 'summit.mercyhurst.edu',
        'port'      => '389',
        'basedn'    => 'DC=mercyhurst,DC=local',
        'userattr'  => 'samaccountname',
        'binddn'    => 'webmaster@mercyhurst.local',
        'bindpw'    => '****',
        'useroc'    => 'user',
        'groupdn'	=> "CN=Users",
        'groupoc'	=> "top",
        'memberattr' => "member"
); $oAuth = new Auth_Container_LDAP($params); $oAuth->options['group'] = "web_administrators"; $oAuth->options['memberisdn'] = false; $return = $oAuth->fetchData("user1", "*****"); if ($return === true) { // user is authenticated and belongs to the group requested } ----> END Here I am instantiating the Auth_Container_LDAP class directly and I am using the fetchData() method to perform: 1. authentication - checking if the username,password pair exists in the
    Active Directory.
2. authorization - checking if the username belongs to the group requested (i.e. "web_administrators").
In this way I was able to nicely integrate the Auth_Container_LDAP functionality into my custom login/session management mechanism. 2 issues that arise by this usage of the package: - not using the wrapper class: Auth, as intended. ! No ability to determine at which point the authentication/authorization process has failed. That means that I cannot communicate to the user of my application if they supplied the wrong password, wrong username or are not authorized to access the application. I think one way of improving the Auth_Container_LDAP class would be to return PEAR_error objects within the fetchData() method, instead of just true/false. The PEAR_error objects could indicate where the problem occurred in the authentication/authorization logic. Regards, -- Lukasz Karapuda VP Application Development - newline Creations LLC. http://www.thenewline.com

« previous php.pear.dev (#32360) next »