Re: Anybody working on SSO class/project ???
| From: | Martin Jansen | Date: | Sun, 02 Jun 2002 17:17:00 +0000 |
| Subject: | Re: Anybody working on SSO class/project ??? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6708@lists.php.net to get a copy of this message | ||
On Sun, 2 Jun 2002 17:02:25 +0200 (CEST), Markus Wolff wrote:
>Yep, maybe we can join forces for such a package. For example, I have
>no experience (at all) with LDAP servers - so all I could do is
>provide the technical possibility to conncet to one, but I wouldn´t
>know how to properly implement data storage and retrieval. Do you have
>experience in that?
A bit, but not enough, I'm afraid.
>All applications, areas and rights are identified by their names. A
>name only has to be unique in its own namespace, ie. you can have an
>autharea "usermanagement" in two different applications, but not two
>areas of the same name within the same application.
>
>You can then define usergroups and assign to them rights within any
>area of any application. Users can belong to an unlimited number of
>usergroups and automatically inherit all rights of the groups they
>belong to.
>
>However, you can also assign rights on a per-user-basis. That means,
>you can give a user individual rights that he doesn´t inherit from any
>group membership. Also, you can define rights that a user may never,
>ever have - even if he´s a member of a usergroup that he normally
>would inherit these rights from.
This sounds good for me, even though I haven't invested much time and
thoughts in a generic user management for PEAR yet. IIRC there were
some people that tried to join forces in order to create a user
management some months ago. Maybe they can clue us in what their ideas
were and how far they went.
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/