Re: Auth_Groups and Auth_Permissions

From: Date: Sun, 15 Aug 2004 03:57:39 +0000
Subject: Re: Auth_Groups and Auth_Permissions
References: 1 2 3 4 5  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-32680@lists.php.net to get a copy of this message
On 15 août 04, at 05:44, Jon Wood wrote:
snip
If you are looking for such a system (true/false only) and you will code from scratch the rest, you probably would code everything from scratch. On the other hand, whomever is looking for a more structured (see Auth source code, I don't see any overhead there...if you don't want the login then you probably don't want an Auth system library either).
I don't think you really understand what this package does - it's not providing login features, because Auth can do that already, it would be duplicating effort to do it again - these packages will simply allow more to be done with the information from Auth than is currently possible within PEAR.
Could be but from the description it looks very basic to me. There is no source yet, is just a draft and I am aware of that. But I believe that the purpose of a draft is to gather some comments before coding it. I am just providing some comments and to me, http://pear.php.net/pepr/pepr-proposal-show.php?id=139 alone as a component, wouldn't fit well/provide a substantial advantage to PEAR users. If I want an Auth system there is one available. Breaking a package functionality in many sub packages with the justification that the new incarnation is lighter doesn't sounds interesting to me. This is again my personal feedback as a pear developer, nothing more, nothing less.
To my the current existing Auth packages on pear (Auth, Liveuser) do cover this category very well.
The Auth class doesn't cover this *at all* - it allows basic logins, and tracking the username of somebody who has logged in. That's it. These classes allow that information to be used more usefully. Like ? I don't really see how you can use the information a different way in an Auth scheme.
Auth might not cover it all but LiveUser does cover a more complex structuring of an authentication system. Your current possible api (e.g. Checks if a user has access. Sets $user to the default access for $permission.) is already covered. I don't see anything new. Using different functions or removing some functionality in the existing packages to make a lightweight version is not sufficient in my opinion. In short, if the purpose of this draft is to gather some initial comments from other developers, I think I made my point clear ;) Regards David Costa

« previous php.pear.dev (#32680) next »