Re: [rfc] permissions managment

From: Date: Wed, 14 Aug 2002 08:46:14 +0000
Subject: Re: [rfc] permissions managment
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-8416@lists.php.net to get a copy of this message
Am Wed, 14 Aug 2002 16:22:37 +0800 schrieb Alan Knowles <alan@akbkhome.com>: > >I don´t quite understand what you mean here... can you describe in more > >detail what your session->object var mapper does? > > > Its a pretty simple little routine, > > > http://docs.akbkhome.com/akpear/HTML_FlexyFramework_Session.html I´ll have a look at this. > >LiveUser allows you to write your own backend classes that can retrieve > >user data from any kind of data source you want. The LoginManager class > >that you use in applications doesn´t need to know how the data is > >actually stored. > > > can you post the link again - I coulnt find it on this thread... :) http://projects.21st-hq.de/liveuser/ > >All profile data, such as ie. adress, gender, credit card numbers and > >the like is stored in one or more separate tables that may change from > >application to application. If a person that has a profile also has an > >online account, its ID in the user table is just referenced in the > >profile table. > > > > > >I really don´t see the need to change the user table for each > >application - it should be used to store always the same kind of data. > > > i do it mainly for speed. - saves an extra sql call to another table.. - > the idea that you can allow a flexible user table means that you could > then apply the infratructure to existing systems - bbforum, midgard .. > or whatever..... or even ldap... Hmm... why would you need another query? Scenario 1: The profile data is not stored within the user object in the session. You´d already know the user´s ID in the user table and can then make _one_ query to find the corresponding profile in another table. Scenario 2: The profile data is stored in the user object - at login time, you can simply do _one_ query to fill your object that joins the two tables together. And as I said, if you want to access another existing system, you can simply write a new backend class for it. You can even configure the LoginManager class to query a list of backend, for example: 1. Look in my own application´s user database ...if the user is not found there... 2. Look in bbforum´s user database ...if the user is not found there... 3. Look in Midgard´s user database ...if the user is not found there... 4. Look in some LDAP server ...if the user is not found there... 5. Query some SOAP server ...if the user is not found there... 6. Query the FBI database One of the next features I´ll add is that you can also have the permissions stored in a separate storage container, so that you can have the login data for a user in any container you want and have his permissions in centralized in one specific container nonetheless. Regards, Markus -- *21st Media* | Consulting, Konzeption, Produktion für die Bereiche: Markus Wolff | Internet, Intranet, eCommerce, Content Management, Hamburg,Germany | Softwareentwicklung, 3D-Animation, Videostreaming http://21st.de | Tel. [+49](0)40/6887949-0, Fax: [+49](0)40/6887949-1

« previous php.pear.dev (#8416) next »