Auth package issues [+PATCH]
| From: | James E. Flemer | Date: | Tue, 23 Jul 2002 19:29:14 +0000 |
| Subject: | Auth package issues [+PATCH] | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-7926@lists.php.net to get a copy of this message | ||
I've been working with the Auth package a little bit and
have some remarks and questions about it.
First it seems that $_SESSION and session_register() /
session_unregister() are both being used. The PHP manual
states that you should not do this.
Second, it seems a bit against the style of the Auth
package to have the storage driver (SD) call
Auth::setAuth(). The only reason for the SD to call
setAuth() is so that the optional second parameter "$data"
can be set (tho no existing SDs do that). However there is
no method to retrieve the "data" after you set it. Yes, I
know it's a session var so you can get it outside the Auth
object ... but why do it this way?
Perhaps to address the second issue, the following change
could be made...
The Auth class would call setAuth() itself if fetchData()
returned true. Two public functions could be added,
setAuthData() and getAuthData() that would deal with any
"extra" information. Perhaps these functions could even be
passed through to the SD.
Oh and one final note, no one seems to be tagging the CVS
tree when they release the package, so I cannot tell very
easily what revision of a file is considered the latest
"STABLE" revision etc (w/o fetching the tgz, untarring and
using ident).
Attached is a patch (against cvs head) addressing the first
two issues. It maintains complete backwords compatability.
I have *NOT* tested the changes for session_(un)register()
because I do not have an old version of PHP running.
-James