Re: Auth_Groups and Auth_Permissions
| From: | Paul M Jones | Date: | Sun, 15 Aug 2004 15:14:27 +0000 |
| Subject: | Re: Auth_Groups and Auth_Permissions | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-32685@lists.php.net to get a copy of this message | ||
Hi, everyone,
Quick overview: I think something like Auth_Groups is needed, and would be a useful (and much-used) addition to PEAR.
----
I know I'm late to the party here, and that there are a lot of emails already on the subject. I'll compile and reply to them all at once, so: sorry in advance for the long email.
I cannot say anything about the Auth_Permissions idea at this time, as I'm not familiar enough with the subject area to provide useful input. My one attempt at abstracted permissions management comes from the access control list in YaWiki, which makes my experience pretty limited.
As such, this email speaks exclusively the Auth_Groups draft, not the permissions draft.
----
Jon Wood wrote:
I've just created proposals for Auth_Groups and Auth_Permissions, which will provide a basic group/permission system for people not wanting to go through the trouble of setting up a full Liveuser/Auth_Enterprise install.I love the Auth_Groups idea; it has been needed for a long time. I was going to approach this myself at some point. I'm not certain it needs to be based on Auth_PrefManager2, as reading from group stores (and maybe writing back to them) is very store-specific and lends itself to a highly-specific container/driver for each store type. (I won't go into detail; that can be discussed later.) However, Auth_PrefManager2 might make a good base after all. Jon, I'm going to take an hour or two today and pick apart the current CVS code, will get back to you on it as regards this. ---- David Costa wrote:
And Jon Wood responded:I wouldn't personally +1 an Auth package because, from my experience, Auth itself is very lightweight. This of course doesn't apply if what you intend to propose is substantially different. From what I saw ( http://pear.php.net/pepr/pepr-proposal-show.php?id=138) what you mention is very close to the package Auth ( don't know about Auth_Enterprise).
This isn't a replacement for Auth, it's an extension - allowing simple management of groups and permissions without the extra overhead involved in the existing solutions, which implement everything (login, permissions, groups, user management etc.) in one package.This is what I understood from Jon's proposal as well. Auth (proper) only does authentication; it does not handle group listings, nor IMO should it. For example, if you need only authentication, you can use Auth (proper). After authentication, you might want to get the groups to which a user belongs; thus, instantiate Auth_Groups and read from a container. You can instantiate as many Auth_Groups objects as you like, to read from different containers. Auth_Groups would not be a replacement for Auth, but an enhancement or add-on to the existing Auth (proper) package. ---- David Costa wrote this:
Jon is entirely free to ignore my comments, move on with a proposal and the relevant code and receive a lot of votes. To me he could better devote his time to more interesting packages.And also this:
I never said that a package has to be huge or earth shattering to be interesting. I just don't see the benefit of it in the Auth branch,I think Auth_Groups is a **fascinating** package proposal, highly interesting and well suited to the Auth branch. If one wants a full-up totally-integrated one-stop-shop does-it-all authentication-groups-permissions-prefs package, then LiveUser is a great candidate solution. But some of us only need an add-on to the existing Auth (proper) to read group information. Auth_Groups sounds perfect for that. ---- Lukas Smith wrote:
Anyways in the end if you want to make this a separate project you should be aware that you will need a lot of maintaing. Auth/Perm packages seem to need a lot of love. :-)Lukas speaks with wisdom and from experience. :-) But Auth (proper) by itself seems to have been very BC-stable (1.3.0 beta issues aside). I cannot think that a group-reader will be that bad; perhaps I will be proved wrong. -- Paul M. Jones Savant: the simple alternative to Smarty for PHP. http://phpsavant.com/ DB_Table: build RDBMS tables and XHTML forms in one PHP class. http://wiki.ciaweb.net/yawiki/index.php?area=DB_Table Yawiki: your collaborative online documentation system. http://yawiki.com/ Yawp: a single-file foundation for PHP applications. http://phpyawp.com/