Comments regarding LDAP container for Auth package (version 1.2.3 Stable).
| From: | Lukasz Karapuda | Date: | Sat, 31 Jul 2004 03:11:55 +0000 |
| Subject: | Comments regarding LDAP container for Auth package (version 1.2.3 Stable). | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-32360@lists.php.net to get a copy of this message | ||
I have used the Auth package to perform authentication against an Ms Active Directory server (version 1.2.3 Stable) within an enterprise web application. I think that the implementation of the LDAP container is very good, however I have several additions/comments about it:
Since my application supports multiple authentication methods, that can be used interchangeably, I have determined that it is not possible for me to use the Auth package in the way it is described in the End-User documentation, i.e.:
$a = new Auth("LDAP", $params, "custom_function");
$a->start();
Hence I basically made a hack and used it in the following way:
----> START
require("Auth/Container/LDAP.php");
$params = array(
'host' => 'summit.mercyhurst.edu',
'port' => '389',
'basedn' => 'DC=mercyhurst,DC=local',
'userattr' => 'samaccountname',
'binddn' => 'webmaster@mercyhurst.local',
'bindpw' => '****',
'useroc' => 'user',
'groupdn' => "CN=Users",
'groupoc' => "top",
'memberattr' => "member"
);
$oAuth = new Auth_Container_LDAP($params);
$oAuth->options['group'] = "web_administrators";
$oAuth->options['memberisdn'] = false;
$return = $oAuth->fetchData("user1", "*****");
if ($return === true) {
// user is authenticated and belongs to the group requested
}
----> END
Here I am instantiating the Auth_Container_LDAP class directly and I am using the fetchData() method to perform:
1. authentication - checking if the username,password pair exists in the Active Directory. 2. authorization - checking if the username belongs to the group requested (i.e. "web_administrators").In this way I was able to nicely integrate the Auth_Container_LDAP functionality into my custom login/session management mechanism. 2 issues that arise by this usage of the package: - not using the wrapper class: Auth, as intended. ! No ability to determine at which point the authentication/authorization process has failed. That means that I cannot communicate to the user of my application if they supplied the wrong password, wrong username or are not authorized to access the application. I think one way of improving the Auth_Container_LDAP class would be to return PEAR_error objects within the fetchData() method, instead of just true/false. The PEAR_error objects could indicate where the problem occurred in the authentication/authorization logic. Regards, -- Lukasz Karapuda VP Application Development - newline Creations LLC. http://www.thenewline.com