Re: We need another Auth
| From: | Martin Jansen | Date: | Mon, 10 Jun 2002 12:06:45 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6859@lists.php.net to get a copy of this message | ||
On Mon, 10 Jun 2002 10:49:42 +0200, Bertrand Mansion wrote:
>I have had so much difficulties to adapt Auth to my own need. The class is
>not flexible enough and might be good for a very basic authentication system
>but not for a complete web application.
>
>I think we need a better authentication system.
That's a very nice thought. If one feels like he is in the position to
say something like this, he should come up with a definitive plan that
tells *what* to improve. Simply busting out that something needs to be
changed is a bit poor. So what do you want to change in detail? Make a
list of the things that need to be changed practically. Provide patches
for the existing system. Do something constructive.
If someone (Markus?) comes up with good improvements, I'll have nothing
against merging them into Auth. I'll even not object against replacing
Auth with something better if the changes are reasonable and BC will be
kept. But simply writing that Auth needs to be dropped in favour of
something better isn't very acceptable yet :).
>This morning, I indexed 35 000 pages using htdig on a website I run
>(http://cocoa.mamasam.com). The indexing crashed because of the way Auth
>handles sessions. I don't understand why there is a session_start() in the
>class start() method. This will start a new session everytime htdig accesses
>a new page. I ended up with 35 000 session files in the session directory !
As far as I see, htdig is fucked up then, no?
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/