Re: Anybody working on SSO class/project ???
| From: | Markus Wolff | Date: | Sat, 01 Jun 2002 18:16:05 +0000 |
| Subject: | Re: Anybody working on SSO class/project ??? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6700@lists.php.net to get a copy of this message | ||
Tomas V.V.Cox said:
> Nicolas Hoizey wrote:
>>
>> Hi everybody,
>>
>> I'm currently trying to design a PHP SSO (Single Sign On)
>> application, and would like to know if anybody has already done
>> anything.
>>
>> I haven't found any SSO project in PHP yet, but I think it should
>> be part of the Auth package. Some people tried to design a User
>> class a while ago, but I don't know if it has given anything.
>
> I don't think it should be part of Auth, I'd say to use it as part
> of the "User" thing.
Hi there,
unfortunately I must have missed the start of this discussion...
what´s the "user" thing? I´ve invested quite some time in this topic
and have already built a user and access rights management class that
is very flexible so that it can easily integrated into the most
different applications.
Currently I´m in the process of rewriting it so that it supports an
arbitrary number of data storage containers (before it only supported
MySQL). When I´m done (and I´m close to finishing it) it will support
several database systems as well as LDAP (using PEAR::DB) and also
SOAP webservices for exchanging data with a storage backend.
The SOAP support will be the first step of providing an SSO
functionality that will work not only across applications, but also
across servers.
It has PHPDoc-Style API documentation and is close to PEAR coding
standards. If there´s interest in this kind of class(es) I´ll put it
up for evaluation.
> I can think on a pluggable architecture where each application
> provides a file with common functions like: addUser(),
> removeUser(), etc. From the central user admin, a call to the main
> addUser() function could call all the app specific addUser() funcs.
Oh and by the way there also already is a nice GUI available that
allows to manage users, groups, authorization areas and rights. It
supports themes, so you can simply change some templates to have its
look & feel match that of your application.
> I guess that this solution is not a real SSO system, it's more a
> "uniform way for handling users" but gives a solution to the
> "disspersed auth systems" problem. Each application needs too
> specific data and I finally get to the point where is really
> difficult (for not saying imposible) to have a unique "container"
> of user data.
This depends on how you define user data. What information would you
like to store about the user?
Regards,
Markus
--
*21st Media* | Consulting, Konzeption, Produktion für die Bereiche:
Markus Wolff | Internet, Intranet, eCommerce, Content Management,
Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming
http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1