Re: [rfc] permissions managment
| From: | Markus Wolff | Date: | Tue, 13 Aug 2002 17:49:47 +0000 |
| Subject: | Re: [rfc] permissions managment | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-8393@lists.php.net to get a copy of this message | ||
On Tue, 13 Aug 2002 19:13:32 +0200
Arnaud Limbourg <arnaud.limbourg@club-internet.fr> wrote:
> > With "one XYZ is enough" you are simply copying existing
> > frameworks like PHPLib. "Multiple XYZ is good" should be
> > the way.
>
> Don't get me wrong, this is not something to apply to every package.
> But since authentication in itself is very simple i don't see the need
> for several XYZ. Of cours, i may be heading the wrong way, that's just
> how i feel about the thing. Reminder, for me authentication is boolean,
> that's why don't see why there should be several packages. Now if
> that's the course we're taking, that's fine with me ;)
You´re right if you´re talking pure authentication - if there´s a good
package, which PEAR::Auth seems to be, there´s not very much reason for
a second one, except perhaps for taste.
Regarding authorisation, I see room for at least two packages: A complex
one with all the options that LiveUser provides, and a very simple one,
like the PHPLib-style permission class. Lukas has plans for separating
the LiveUser package into three levels of complexity, which I guess I
don´t fully understand at this point.
> There was talk about a Single Sign On project as well.
Yes, that was proposed by Kristian Köhntopp, and I have also had some
talks with Björn Schotte about this topic, but there isn´t any code yet.
Many of the features for such a system that they have proposed are on
the todo-list for LiveUser, so that a SSO system will be possible with
LiveUser in the future.
Regards,
Markus
--
Markus Wolff <wolff@21st.de>