Re: We need another Auth
| From: | Pierre-Alain Joye | Date: | Mon, 10 Jun 2002 13:38:52 +0000 |
| Subject: | Re: We need another Auth | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6880@lists.php.net to get a copy of this message | ||
On Mon, 10 Jun 2002 15:19:04 +0200
Michael Haertl <mhaertl@emiga.de> wrote:
>
>
> Markus Wolff wrote:
> > I didn´t have an in-depth look at PEAR::Auth, but from what I´ve seen,
> > it resembles the functionality you could achieve with standard .htaccess
> > basic authentication while being able to use a database for storing
> > usernames and passwords. It does not, for example, have the ability to
> > associate certain rights (like "user may read", "user may write",
> > "user
> > may make coffee" etc.) with certain users in one or more applications.
> > Martin, please correct me if I´m wrong here.
Especially, take a look to the optional data you can load. I use Auth for a simple (one level)
permission system. Auth is really opened and and may be used as the authentification module for a
permission module.
> PEAR::Auth := "Authentication"
> "Authentication" != "Authorization"
>
> IMHO your rights management should not be part of a pure authentication
> class like PEAR::Auth.
It's exactly the conclusion people got during the last discussion about
"Authentification".
We do not have to be confused between permissions and authentifications, same for secure a site and
authenfication. Authentification is only a part of the job to secure a site.
pa