getUserID() and getGroupID() in PEAR::Auth?
| From: | Alessandro Bottoni | Date: | Thu, 19 Jun 2003 09:51:31 +0000 |
| Subject: | getUserID() and getGroupID() in PEAR::Auth? | ||
| Groups: | php.pear.general | ||
| Request: | Send a blank email to pear-general+get-6115@lists.php.net to get a copy of this message | ||
Yes, you are right: there is not any getUserID() and/or getGroupID() function
inside the PEAR Auth module. Actually, PEAR Auth does not even support the
concept of user groups.
And that is my problem: I'm looking for a (possibly standard or largely used)
Authentication module that supports the concept of user groups and can give
me the userID and the groupID on request. Of course, the userID is NOT the
same thing as a username: it is a unique identifier (possibly a MD5 value or
a Unix UUID) that can be used, for example, as a custom Primary Key in a
RDBMS.
I wonder if anybody has derived a class from PEAR Auth and/or PEAR
Auth_Container_DB for implementing such concepts. (The concept of Group
cannot be implemented with a Container that cannot support it, of course).
I mean: a special version of PEAR Auth that (when used together with
Container_DB and other containers that can support this feature) can provide
these functions:
- getUserID() -> returns a MD5 or UUID that identify the user
- getGroupID() -> returns an array with the MD5/UUID iof the groups the user
belongs to
- addUserToGroup(UserID, GroupID) -> boolean
- removeUserFromGroup(UserID, GroupID) -> boolean
- addGroup()GroupID -> boolean
along with the existing functions:
addUser() -> booean
getUsername() -> username (string)
This would allow me to implement a Unix-like permissions system:
- assign your page (or dir) to a "owner" (a user and, if required, a group)
- give your page (or dir) a set of required access rights like "rw-rw-r--"
- check the UserID and the groupID of the people who wants to access the page
- act consequently (allow/deny the access)
I had a look at the PEAR Auth code and it looks like that this feature could
be (almost) easily implemented by redefining the fetchData function of
Auth_Container (and derived classes) so, I think it is possible that someone
has already did it.
Any link?
---------------------
Alessandro Bottoni