Re: Anybody working on SSO class/project ???
| From: | Jens Fischer | Date: | Fri, 31 May 2002 13:09:38 +0000 |
| Subject: | Re: Anybody working on SSO class/project ??? | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6682@lists.php.net to get a copy of this message | ||
Hello Nicolas,
Friday, May 31, 2002, 1:53:57 PM, you wrote:
> Hi everybody,
First of all I am new to this list, so Hello to everybody
participating in here. I have several years of PHP experience and got
to love the PEAR approach some months ago.
> I'm currently trying to design a PHP SSO (Single Sign On) application,
> and would like to know if anybody has already done anything.
> I haven't found any SSO project in PHP yet, but I think it should be
> part of the Auth package. Some people tried to design a User class a
> while ago, but I don't know if it has given anything.
Same problem here. I am currently having the same need, but since I
didn't find anything suitable on the 'net I decided to come up with my
own version. What I am currently developing is a Model-View-Controller
application framework based on PEAR. Basically it's a rewrite of the
Jakarta Struts MVC framework made for Java
( http://jakarta.apache.org/struts ), which should
support I18N and SSO
in the end. It's not meant as a fully featured web application, but
more in the spirit of a framework one can use to build the specific
application on top. But since I (and a small team of other developers)
started with this project only one week ago there's nothing
spectacular finished right now. Let's see what will come out in the
end.
> The simple way would be to patch all application so that they use the
> same auth application, but it would break compatibility with those
> application updates.
I wouldn't even dare trying to patch existing applications to nicely
integrate with SSO. You have to invest so much time, that in the end
you'll be quicker when you do it from scratch, in a very generic and
abstract way. Plus you get reusable codem, which fully fits your
needs.
> The best way is then to provide an application that stands on top of
> all others, and give the ability to use one single authentication to
> access to those others. It needs to know how each application performs
> auth and "simulate" it for any user.
ACK. That's why I decided to start working on an application
framework.
> Do you have any idea or do you know any existing script ?
> Regards,
> -Nicolas
CU,
Jens