Welcome Guest, Not a member yet? Register   Sign In
Auth
#31

(This post was last modified: 11-25-2014, 02:58 PM by twpmarketing.)

I totally agree with Narf and bclinton on the idea of a "built-in" auth utility.
I use both a very simple user registration system and a more complex authorization tool.
I wrote both (sorry, they are owned by my clients) and the complex system is just that, complex. It has to be to meet the needs of the program/application.

No, it is not a good idea to make a general purpose auth tool because it is far too easy to hack it from external systems. Do what bclinton advises, above, and analyze your real needs for the system. Perhaps you can get by with a simple registration system. And perhaps you cannot because you need the complex, secure features of a full auth system. But it is up to you to decide. It is not and should not be the responsibility of the CI developers and maintainers to keep > Your < security system truly secure.

That being said, I would really like to see someone address, in the CI world, just what needs to be included in an auth system. A "How-to" on Auth, oriented to CI3, singleton, PHP 5.x. There are plenty of books on the subject and they are still an uphill climb to digest and they generally are not CI oriented.
/rant off

[edit] I'd like to see a separate sub-forum, here, to address authorization and security issues. The 'net is not getting any more secure and we could all use some feedback on what is happening and how it might be addressed under CI...
CI 3.1 Kubuntu 19.04 Apache 5.x&nbsp; Mysql 5.x PHP 5.x PHP 7.x
Remember: Obfuscation is a bad thing.
Clarity is desirable over Brevity every time.


Messages In This Thread
Auth - by zurtri - 10-29-2014, 03:57 PM
RE: Auth - by skunkbad - 10-29-2014, 06:24 PM
RE: Auth - by kilishan - 10-29-2014, 07:57 PM
RE: Auth - by zurtri - 10-29-2014, 10:35 PM
RE: Auth - by InsiteFX - 10-30-2014, 06:34 AM
RE: Auth - by Hobbes - 10-30-2014, 06:51 AM
RE: Auth - by includebeer - 10-30-2014, 07:39 AM
RE: Auth - by tristian - 11-07-2014, 06:35 AM
RE: Auth - by Shawn P - 11-12-2014, 04:38 PM
RE: Auth - by Avenirer - 10-30-2014, 08:21 AM
RE: Auth - by no1youknowz - 10-30-2014, 09:46 AM
RE: Auth - by BrandF - 10-31-2014, 08:20 AM
RE: Auth - by GrigoreMihai - 11-06-2014, 07:08 AM
RE: Auth - by GeorgeD - 11-06-2014, 08:23 AM
RE: Auth - by dmyers - 11-06-2014, 11:55 AM
RE: Auth - by GrigoreMihai - 11-06-2014, 11:46 PM
RE: Auth - by Narf - 11-07-2014, 03:05 AM
RE: Auth - by GrigoreMihai - 11-07-2014, 03:26 AM
RE: Auth - by bclinton - 11-16-2014, 10:15 PM
RE: Auth - by benoni - 11-07-2014, 04:23 AM
RE: Auth - by Tim Brownlaw - 11-12-2014, 05:09 PM
RE: Auth - by Chroma - 11-14-2014, 08:48 AM
RE: Auth - by sv3tli0 - 11-17-2014, 12:09 AM
RE: Auth - by bertansh - 11-17-2014, 05:29 AM
RE: Auth - by Rufnex - 11-17-2014, 07:11 AM
RE: Auth - by tomlagard - 11-24-2014, 08:50 PM
RE: Auth - by sv3tli0 - 11-25-2014, 02:04 AM
RE: Auth - by Tux - 11-25-2014, 05:15 AM
RE: Auth - by Narf - 11-25-2014, 06:23 AM
RE: Auth - by bclinton - 11-25-2014, 09:50 AM
RE: Auth - by twpmarketing - 11-25-2014, 02:54 PM
RE: Auth - by bclinton - 11-25-2014, 05:39 PM
RE: Auth - by alroker - 11-25-2014, 04:16 PM
RE: Auth - by sv3tli0 - 11-26-2014, 12:08 AM
RE: Auth - by alroker - 11-26-2014, 01:02 AM
RE: Auth - by includebeer - 11-26-2014, 08:48 PM
RE: Auth - by jlp - 11-26-2014, 10:52 PM
RE: Auth - by kilishan - 11-26-2014, 11:51 PM
RE: Auth - by jlp - 11-27-2014, 12:07 AM
RE: Auth - by alroker - 11-27-2014, 01:12 AM
RE: Auth - by Narf - 11-27-2014, 07:38 AM
RE: Auth - by hvmitev - 11-27-2014, 08:02 AM
RE: Auth - by bclinton - 11-27-2014, 10:35 AM
RE: Auth - by bclinton - 11-27-2014, 10:45 AM
RE: Auth - by alroker - 11-27-2014, 10:28 AM
RE: Auth - by no1youknowz - 11-27-2014, 10:55 AM
RE: Auth - by includebeer - 11-27-2014, 12:38 PM
RE: Auth - by sv3tli0 - 11-27-2014, 01:09 PM
RE: Auth - by alroker - 11-27-2014, 05:36 PM
RE: Auth - by bclinton - 11-27-2014, 09:11 PM
RE: Auth - by GeorgeD - 11-28-2014, 03:59 AM
RE: Auth - by sv3tli0 - 11-28-2014, 05:56 AM
RE: Auth - by includebeer - 11-28-2014, 06:30 AM
RE: Auth - by sv3tli0 - 11-28-2014, 07:02 AM
RE: Auth - by bclinton - 11-28-2014, 07:57 AM
RE: Auth - by sv3tli0 - 11-28-2014, 08:14 AM
RE: Auth - by includebeer - 11-28-2014, 09:10 AM
RE: Auth - by ivantcholakov - 11-28-2014, 07:34 AM
RE: Auth - by no1youknowz - 11-28-2014, 08:32 AM
RE: Auth - by DonOzone - 11-28-2014, 01:05 PM
RE: Auth - by zurtri - 11-28-2014, 05:56 PM



Theme © iAndrew 2016 - Forum software by © MyBB