Re: [rfc] permissions managment
| From: | Markus Wolff | Date: | Wed, 14 Aug 2002 08:46:14 +0000 |
| Subject: | Re: [rfc] permissions managment | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-8416@lists.php.net to get a copy of this message | ||
Am Wed, 14 Aug 2002 16:22:37 +0800 schrieb Alan Knowles <alan@akbkhome.com>:
> >I don´t quite understand what you mean here... can you describe in more
> >detail what your session->object var mapper does?
> >
> Its a pretty simple little routine,
>
>
> http://docs.akbkhome.com/akpear/HTML_FlexyFramework_Session.html
I´ll have a look at this.
> >LiveUser allows you to write your own backend classes that can retrieve
> >user data from any kind of data source you want. The LoginManager class
> >that you use in applications doesn´t need to know how the data is
> >actually stored.
> >
> can you post the link again - I coulnt find it on this thread... :)
http://projects.21st-hq.de/liveuser/
> >All profile data, such as ie. adress, gender, credit card numbers and
> >the like is stored in one or more separate tables that may change from
> >application to application. If a person that has a profile also has an
> >online account, its ID in the user table is just referenced in the
> >profile table.
> >
> >
> >I really don´t see the need to change the user table for each
> >application - it should be used to store always the same kind of data.
> >
> i do it mainly for speed. - saves an extra sql call to another table.. -
> the idea that you can allow a flexible user table means that you could
> then apply the infratructure to existing systems - bbforum, midgard ..
> or whatever..... or even ldap...
Hmm... why would you need another query?
Scenario 1: The profile data is not stored within the user object in the
session. You´d already know the user´s ID in the user table
and can then make _one_ query to find the corresponding
profile in another table.
Scenario 2: The profile data is stored in the user object - at login
time, you can simply do _one_ query to fill your object that
joins the two tables together.
And as I said, if you want to access another existing system, you can
simply write a new backend class for it. You can even configure the
LoginManager class to query a list of backend, for example:
1. Look in my own application´s user database
...if the user is not found there...
2. Look in bbforum´s user database
...if the user is not found there...
3. Look in Midgard´s user database
...if the user is not found there...
4. Look in some LDAP server
...if the user is not found there...
5. Query some SOAP server
...if the user is not found there...
6. Query the FBI database
One of the next features I´ll add is that you can also have the
permissions stored in a separate storage container, so that you can have
the login data for a user in any container you want and have his
permissions in centralized in one specific container nonetheless.
Regards,
Markus
--
*21st Media* | Consulting, Konzeption, Produktion für die Bereiche:
Markus Wolff | Internet, Intranet, eCommerce, Content Management,
Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming
http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1