Re: Auth_Groups and Auth_Permissions

From: Date: Sun, 15 Aug 2004 04:04:10 +0000
Subject: Re: Auth_Groups and Auth_Permissions
References: 1 2 3 4 5 6  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-32681@lists.php.net to get a copy of this message
On Sun, 15 Aug 2004 05:57:39 +0200, David Costa <gurugeek@php.net> wrote: > > On 15 août 04, at 05:44, Jon Wood wrote: > >> > > snip > > > >> If you are looking for such a system (true/false only) and you will > >> code from scratch the rest, you probably would code everything from > >> scratch. > >> On the other hand, whomever is looking for a more structured (see Auth > >> source code, I don't see any overhead there...if you don't want the > >> login then you probably don't want an Auth system library either). > >> > > I don't think you really understand what this package does - it's not > > providing login features, because Auth can do that already, it would > > be duplicating effort to do it again - these packages will simply > > allow more to be done with the information from Auth than is currently > > possible within PEAR. > > Could be but from the description it looks very basic to me. There is > no source yet, is just a draft and I am aware of that. > But I believe that the purpose of a draft is to gather some comments > before coding it. I am just providing some comments and to me, > http://pear.php.net/pepr/pepr-proposal-show.php?id=139 alone as > a > component, wouldn't fit well/provide a substantial advantage to PEAR > users. > > If I want an Auth system there is one available. Breaking a package > functionality in many sub packages with the justification that the new > incarnation is lighter doesn't sounds interesting to me. This is again > my personal feedback as a pear developer, nothing more, nothing less. > > > >> To my the current existing Auth packages on pear (Auth, Liveuser) do > >> cover this category very well. > > The Auth class doesn't cover this *at all* - it allows basic logins, > > and tracking the username of somebody who has logged in. That's it. > > > > These classes allow that information to be used more usefully. > > > Like ? I don't really see how you can use the information a different > way in an Auth scheme. > By allowing the grouping of users, and checking permissions. Auth doesn't allow this at the moment without custom writing the same code that everybody else has written 10 times before. These packages are intended to provide a simple solution to that problem. > Auth might not cover it all but LiveUser does cover a more complex > structuring of an authentication system. > Your current possible api (e.g. Checks if a user has access. Sets $user > to the default access for $permission.) is already covered. I don't see > anything new. Using different functions or removing some functionality > in the existing packages to make a lightweight version is not > sufficient in my opinion. > Can you please point out *where* it is covered - LiveUser doesn't count, since it's virtually undocumented, too much hassle to get working, and tries to do everything. I'm aware that this may not seem like a huge, earth-shattering package, but it was never intended to be - it's meant to be a small, light, package, which does one job well. I believe that is the description of what a PEAR package should be in the manual. > In short, if the purpose of this draft is to gather some initial > comments from other developers, I think I made my point clear ;) > > Regards > David Costa > >

« previous php.pear.dev (#32681) next »