Re: Auth_Groups and Auth_Permissions

From: Date: Sun, 15 Aug 2004 08:58:53 +0000
Subject: Re: Auth_Groups and Auth_Permissions
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-32684@lists.php.net to get a copy of this message
Jon Wood wrote:
This isn't a replacement for Auth, it's an extension - allowing simple management of groups and permissions without the extra overhead involved in the existing solutions, which implement everything (login, permissions, groups, user management etc.) in one package. It's mainly designed as a direction to go in for people already using Auth for login management, who would like to extend the capabilities of their application without ripping out all the auth stuff and starting again.
Using LiveUser is insanely simple inside your code. However you need to setup a fairly complex configuration array. We could probably do a better job at setting defaults to make the process simpler. The biggest drawback to LiveUser is that its very complex on the inside. Alot of people are scared off by that, especially since people want to understand what is happening when it comes to security. This is not something we can get rid of. For example the separation of the auth and perm stuff is complicated. And then we have other complicated features. However the source of our simple container is actually very easy to grasp (it has permissions but no groups). The source of the medium container is also not rocket science yet. The source of the complex container is getting closer to rocket science though. I remember Jon or someone else talking about a package like this before. And my answer back then iirc was essentially we still have a few things we can do to LiveUser to make it simpler. However flexibility and features are things we dont want to give up in LiveUser so there are limits. But as I am writing this it just came to my mind. You could write a backend based on our Auth wrapper. That provides a totaly streamedlined solution for the perm part as well. This backend would use a very simpel database schema. It would not separate the auth tables from the perm tables etc. Now if we were to separate the drivers from the core, which makes sense also for future development we would end up with something like a LiveUser core framework package and then a bunch of driver packages. Maybe a good start is for you to look at LiveUser.php and see if you are comfortable with this code for your proposal. Also I dont know how well you know LiveUser.php, but if you can name anything what makes LiveUser too complicated in your eyes maybe the LiveUser guys can help you if its possible to remove this complexity with a streamlined driver or not. Anyways in the end if you want to make this a separate project you should be aware that you will need a lot of maintaing. Auth/Perm packages seem to need a lot of love. :-) regards, Lukas

« previous php.pear.dev (#32684) next »