Re: We need another Auth
| From: | Markus Wolff | Date: | Mon, 10 Jun 2002 12:57:07 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6868@lists.php.net to get a copy of this message | ||
Am Mon, 10 Jun 2002 14:28:53 +0200 schrieb Bertrand Mansion <bmansion@mamasam.com>:
> > If someone (Markus?) comes up with good improvements, I'll have nothing
> > against merging them into Auth. I'll even not object against replacing
> > Auth with something better if the changes are reasonable and BC will be
> > kept. But simply writing that Auth needs to be dropped in favour of
> > something better isn't very acceptable yet :).
>
> We probably won't have to replace the current Auth class. It just depends if
> Markus'class does the same in a better way and if the APIs are compatible or
> not. If the APIs are different, then we will probably need to have two Auth
> classes which I have nothing against as long as they have different names.
>
> There are more than one html form class in pear, there are more than one
> template class in pear...
I guess that´s the way it would be - having two separate authentication
systems that do things differently.
I didn´t have an in-depth look at PEAR::Auth, but from what I´ve seen,
it resembles the functionality you could achieve with standard .htaccess
basic authentication while being able to use a database for storing
usernames and passwords. It does not, for example, have the ability to
associate certain rights (like "user may read", "user may write", "user
may make coffee" etc.) with certain users in one or more applications.
Martin, please correct me if I´m wrong here.
My class focuses on user rights management. It was last week´s
discussion where the point was brought up that PEAR could use a standard
authentication and rights management system so that different
applications using this system could work together more smoothly,
without the need for workarounds and hacks to make each application
recognize user accounts or userrights of the other(s).
Of course, simple authentication (is this user logged in or not?) comes
with it automatically, but things are managed way differently than in
PEAR::Auth.
On the other hand, if you don´t need excessive rights management, my
class would be pure overkill. PEAR::Auth is the way to go if you want
simplicity.
So I think there´s more than enough room for both classes.
Just wait a few more days, it´ll become clear what I mean, then.
Regards,
Markus
--
*21st Media* | Consulting, Konzeption, Produktion für die Bereiche:
Markus Wolff | Internet, Intranet, eCommerce, Content Management,
Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming
http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1