[rfc] permissions managment
| From: | robert janeczek | Date: | Mon, 12 Aug 2002 21:24:29 +0000 |
| Subject: | [rfc] permissions managment | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-8335@lists.php.net to get a copy of this message | ||
i think its the time to think about perms class(es). i exchanged some emails
with martin jensen about it. we agreed that there is a need for such
functionality. during the discussion we came to something like this:
- new category (probably Perm) or subcategory in Auth
- rather few classes than one
why multiple classes? there are two basic categories of perms system needed:
for basic use and for advanced use. the first one is when you need something
more than Auth class but not to complicated. my idea is (as shown earlier
here) simple binary encoded perms value, ie.
perms['Student'] = 1;
perms['Moderator'] = 2;
perms['Administrator'] = 4;
...
(this array would be only needed for displaying permissions desription)
in a container there would be one more field needed for storing perms (ie.
moderator + administrator = 2 | 4). i think you all get the idea - its
simplest perms system possible imho. it is ready - it required few changes
in auth class and in container (currently db container works, i haven`t
tried it with the other ones).
this is enough for 99% of website`s, but probably not enough for over 50% of
enterprise class applications. so - this is why second class is needed. i
received a short description of something like this from tim gallagher (i
might be wrong, but hopefuly it was him :)) - a perms managment system that
requires a website to be fully used. i didn`t quite get all the ideas
standing behind it so i think it would be best for us if tim had shown us
the description to discuss it. i`m not sure that the idea can be realized
extending Auth class, but it shouldn`t be a problem - the class could do on
its own.
the discussion we should have here is:
- to do or not to do?
- where to place this in pear structure?
- who is going to make it? :)
- everything more you think should be discussed here
rashid