Re[2]: [PEAR] Some questions about LiveUser

From: Date: Sat, 06 Dec 2003 13:56:38 +0000
Subject: Re[2]: [PEAR] Some questions about LiveUser
References: 1 2  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-9329@lists.php.net to get a copy of this message
hi Markus, thanks for your answer! > Currently there is no entity called "role" in LiveUser. We have had > more than one discussion if it should be integrated, but the > perceptions what a role is and what it should do in an application > differ too much - obviously, there is no real standard fore a > role-based permission system, every application handles it > differently. That's why we think it's best to let roles be handled by > the application, not LiveUser. > BUT... all that you've described can already be done using groups. You > can assign a set of permissions to a group, so that would basically be > your "role". Users who are assigned to a number of groups will inherit > all their permission settings. "Classes" would be groups as well. > In our discussions we have always concluded that there's nearly > nothing you can't do with just assigning groups. Everything else is > really more a question of defining new words for things that have > already existed before. that's what I thought. so I use the groups feature to implement what I refere to as role and use it again to implement classes. so on the application level both will be the same, but on usage these two kinds of groups will differ. right? that would not satisfy my needs really.. :-( >> second: >> I like the database abstraction in LiveUser using PEAR::DB. but is it >> possible to use PEAR::DB_ldap[2] also? > It's not possible to use DB_ldap with the existing LiveUser > containers, as they all send normal SQL queries to DB, which LDAP > won't understand. I understood that LiveUSer will use PEAR::DB as an interface for database access, this should be able to extend to PEAR::DB_ldap[2] right? so that there's a SQL-to-LDAP translation in between..? > although I don't think I've fully understood what you mean by > "accounts of the second will be aliased on the local one"... an alias is an ldap feature. it means that an ldap server creates a link to an account on a second ldap server rather than creating the account redundantly. if asked, the ldap will reply with some sort of 'I do not have that account you're asking for, but I know who might got it'. gruss /Christian mailto:caefer@krachstoff.net -- I propose that the following character sequence for joke markers: :-) 19-Sep-82 11:44 Scott E Fahlman

« previous php.pear.general (#9329) next »