Re: A registration with a common userbase?
| From: | Manuel Lemos | Date: | Sun, 30 Jun 2002 07:15:02 +0000 |
| Subject: | Re: A registration with a common userbase? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-7413@lists.php.net to get a copy of this message | ||
Hello,
On 06/30/2002 03:06 AM, Kristian Koehntopp wrote:
Is anyone interested into establishing a user login class and infrastructure, a kind of passport system? The respective class would use an external or distributed database to validate the user against that database. It would also enable registration to that database, perhaps also adding additional data about that user to the central store. The class would also have an optional, local storage component with additional user data such as preferences, customizations and similar, which need or should not be shared to a central store. The class would allow a user to roam freely between sites that are using this class to authenticate users.Depending on your constraints you problem may very simple or extremely complex. Do the site share a common domain like .yahoo.com? If so, this would simplify a lot by setting session cookies under the same domain. If not, after authenticating you would have to redirect the browser to some page in the network site so it can set a session cookie for its domain. Retrieving user profile data is not a big problem. Even if you are in heterogenous network (Windows, Unix, etc) SOAP is a perfect fit. The biggest problem is handling updates of the user profile data. Ideally you would redirect to the browser to each site to force some profile data update, but that is not really viable. Some sites store common user profile data in the session cookies using some secret key. Although that is not very safe in case of secret key disclosure, it is probably the most scalabale solution as decrypting user profile data is usually faster than retriving it from a database on every access where it is needed. OTHO, it would be harder to handle user profile updates. The possibilities are vast. So, it would be probably better if you could tell more about your constraints not avoid thinking abouth the solutions that depend on those constraints. -- Regards, Manuel Lemos