Re: We need another Auth
| From: | Markus Wolff | Date: | Mon, 10 Jun 2002 09:45:20 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6839@lists.php.net to get a copy of this message | ||
Am Mon, 10 Jun 2002 10:49:42 +0200 schrieb Bertrand Mansion <bmansion@mamasam.com>:
> I think we need a better authentication system.
We had a small discussion about that last week (I think). In short, yes
we do.
I´ve developed a user authentication and rights management system that
can be used in almost every environment and that I´m currently rewriting
to be independent of a specific datasource (before, you could store user
data only in MySQL, with the new version you´ll be able to use any
database, LDAP server or even a SOAP webservice for user authentication).
When I´m done (most likely by the end of this week), I´ll post a link to
the sources and API doc so that it can be considered for inclusion in
PEAR.
> This morning, I indexed 35 000 pages using htdig on a website I run
> (http://cocoa.mamasam.com). The indexing crashed because of the way Auth
> handles sessions. I don't understand why there is a session_start() in the
> class start() method. This will start a new session everytime htdig accesses
> a new page. I ended up with 35 000 session files in the session directory !
>
> This is silly. There might for sure be some other solutions but if so, it is
> not explained in the source or in the docs.
Good point. I wrote a login manager class for my authentication system
that does the same thing, but I didn´t think about indexers (actually
you don´t _have_ to use the manager class to use the authentication
system, but it makes things a LOT more convenient).
Question is: How does one solve the authentication problem without using
a session?
> BTW, I checked the web for other authentication system and couldn't find any
> good one (which works with register_globals off, which handle sessions
> correctly, which allows for a 'remember me' checkbox...). If someone has a
> link, I will be glad to see it. TIA
The abovementioned system handles all these cases, I´m just not sure if
it´ll match your definition of handling sessions correctly (some more
insight in what you think would be proper handling might help). And as I
said, I´ll propose it by the end of this week for inclusion in PEAR.
Regards,
Markus
--
*21st Media* | Consulting, Konzeption, Produktion für die Bereiche:
Markus Wolff | Internet, Intranet, eCommerce, Content Management,
Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming
http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1