RE: [PEAR-DEV] liveUser (was: Re: permissions managment)
| From: | Lukas Smith | Date: | Tue, 13 Aug 2002 11:13:10 +0000 |
| Subject: | RE: [PEAR-DEV] liveUser (was: Re: permissions managment) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-8356@lists.php.net to get a copy of this message | ||
> -----Original Message-----
> From: Markus Wolff [mailto:wolff@21st.de]
>
> the class first reads all individual rights for the user and all
rights
> he inherits from his membership in any groups. These two arrays are
then
> merged to one array and individual rights will override group rights
in
> the process (ie. you can have a right "make coffee" because you´re a
> member of the coffee group, but if your individual rights say that
> making coffee is specifically denied, you can´t do that :-)).
>
> This all happens at login time. After one, no request to the storage
> container is made throughout the entire session because all rights are
> stored within the user object that is stored in the session.
> I think the performance of this should be much higher than doing a
query
> to the storage container every time.
>
I am not so sure of that.
How many rights are requested per page load in a common app versus how
many rights could you possible have?
For example:
User login to the admin site to add a new news entry.
On the first page he is shown the list of all modules.
On this page I will need to figure out what modules he has access to: 1
request
He then clicks on the news module and I will need to check what specific
rights he has to the news module: 1 request (+1 request if I want to
keep the list of modules that he has access to in the menu)
He then clicks on add new entry: 1 request (+1 request if I want to keep
the list of modules that he has access to in the menu)
He then adds the entry and is displayed the result: 1 request (+1
request if I want to keep the list of modules that he has access to in
the menu)
But in this application there are about 10 modules with on average 5
different rights = 50 different rights that can either be a user right
or a group right. Dunno if your system already allows this but I would
want the users to be able to be in multiple groups as well.
So what I would prefer is to simply store all results from a check into
the rights array so that during one request a check is never done
multiple times.
You can then query for a specific right, for all rights for that module
or all rights.
If you have queried for all rights of a module or all rights you would
have to store this fact so that if the user does not have the right it
does not think that it has to query the backend (I am assuming that you
only store the rights that the user has not which rights the user does
not have).
So if you structure your application correctly you can ensure that you
never first to a specific check on a module that you later do a global
check module on.
Does this make sense?
Maybe we should talk about this on IRC
Regards,
Lukas