• 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
CI4 User Authentication System

#10
I agree with skunkbad entirely. I already grimaced at some of the earlier 'requirements' but look at the bloat being suggested now. So whatever you do it will either be 'too bloated' for half the people and 'not powerful enough' for the other half.

Take 'forgotten password' for instance. There are so many ways to do just that alone. Secret questions, emailing reset links, emailing codes to reset, sending temp passwords, second one time use passwords, sending random passwords, human moderation of password resets etc etc. And then what about lost access to email accounts, 2 step verifications, enforcing change passwords, password complexity demands etc. And that is just one tiny thing most users experience as a standard 'forgot password', but what actually happens in the background can be done in so many different ways.

There is no best way, there is secure or not secure, user friendly or not user friendly, simple and not simple. But how secure, user friendly or simple you want to be depends on the site you are building. You cannot win with a single solution that supposedly fits all. And that is just for 'forgotten password'. Even just the way you store a password will cause issues. Let alone more complex user related things like sign up and account creation.

I think this is really good advice so I am going to quote it again.  
(03-04-2017, 06:40 PM)skunkbad Wrote: I don't want to discourage you, but rather hope that you don't make mistakes thinking that what you want is even remotely ideal. You should definitely carry on with your project, and plan to spend 100s of hours on it. It happened to me. Great learning experience. I started my authentication project about 10 years ago. I thought that people would be excited, and that there would be a community that wanted it, and would want to help with it. Heck, I even named my authentication "Community" Auth. My advice is, plan to do most of the work on your own, or you might be disappointed.

Anyway, having said all that, when you have an alpha version I will happily test it for you. Look forward to trying it out.

Best wishes,

Paul.
Reply


Messages In This Thread
CI4 User Authentication System - by ajturner - 03-03-2017, 11:07 AM
RE: CI4 User Authentication System - by kilishan - 03-03-2017, 04:03 PM
RE: CI4 User Authentication System - by atishamte - 03-03-2017, 10:31 PM
RE: CI4 User Authentication System - by ajturner - 03-04-2017, 07:07 AM
RE: CI4 User Authentication System - by ajturner - 03-04-2017, 09:29 AM
RE: CI4 User Authentication System - by kierownik - 03-04-2017, 12:31 PM
RE: CI4 User Authentication System - by visualsol - 03-04-2017, 05:02 PM
RE: CI4 User Authentication System - by skunkbad - 03-04-2017, 06:40 PM
RE: CI4 User Authentication System - by PaulD - 03-04-2017, 08:30 PM
RE: CI4 User Authentication System - by Narf - 03-06-2017, 02:51 AM
RE: CI4 User Authentication System - by qury - 03-06-2017, 05:48 AM
RE: CI4 User Authentication System - by ajturner - 03-06-2017, 07:14 AM
RE: CI4 User Authentication System - by Narf - 03-06-2017, 07:41 AM
RE: CI4 User Authentication System - by ajturner - 03-06-2017, 08:15 AM
RE: CI4 User Authentication System - by qury - 03-06-2017, 10:25 AM
RE: CI4 User Authentication System - by cartalot - 03-06-2017, 11:13 AM
RE: CI4 User Authentication System - by qury - 03-06-2017, 11:50 AM
RE: CI4 User Authentication System - by skunkbad - 03-06-2017, 04:48 PM
RE: CI4 User Authentication System - by visualsol - 03-06-2017, 10:53 PM
RE: CI4 User Authentication System - by ajturner - 03-09-2017, 08:32 AM
RE: CI4 User Authentication System - by kilishan - 03-09-2017, 01:36 PM

Digg   Delicious   Reddit   Facebook   Twitter   StumbleUpon  


  Theme © 2014 iAndrew  
Powered By MyBB, © 2002-2020 MyBB Group.