[PEPr] Comment on HTTP::HTTP_FloodControl
| From: | Vagharshak Tozalakyan | Date: | Mon, 05 Mar 2007 15:37:14 +0000 |
| Subject: | [PEPr] Comment on HTTP::HTTP_FloodControl | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-45819@lists.php.net to get a copy of this message | ||
Vagharshak Tozalakyan (http://pear.php.net/user/vagharsh) has commented on the proposal for
HTTP::HTTP_FloodControl.
Comment:
>> I think you should make it a PHP5 package and use class constants
instead of defines and exceptions instead of pear errors. Or make your
defines more standard, using a longer prefix to avoid collisions.
Sure, among other things it will allow to use different object-oriented
features (e.g. abstract classes for storage drivers). The only reason
because of which I have written a PHP4 compatible code is that many shared
hosting servers do not support PHP5 till now. I'm a novice to PEAR
development and would like to know what version of PHP is prefered to use
for new packages?
Also I would like to know is there any recommendations on how to
construct name prefixes of defined constants?
>> I am also afraid $_SERVER['REMOTE_ADDR'] is not reliable, especially if
users are behind a router/proxy (they will share the same IP and they might
be quickly locked out on big traffic or big corporate sites where users all
connect at the same hour in the morning...).
I agree with you on that issue, that's why I decided to allow the users to
define a control criterion they will prefer as the second parameter of
check() method. It may be a real IP address detected by one of the
methods, an address of a subnet, a session identifier, a fingerprint
calculated custom way, etc. What do you think , is it necessary to impose
an IP detection method on the user?
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=476
--
Sent by PEPr, the automatic proposal system at http://pear.php.net