I want to start a bit of discussion on the auth system in Moin at the moment.

It has a few problems as far as I'm concerned (which I have patches to deal with), but I think the issue is a bit wider than that.

Problems

Solutions

I use the attached patch bundles. These provide a distinct moin_session cookie mechanism, use LDAP "properly" (i.e. doesn't store the password, and don't assume moin_cookie will follow).

It's an improvement, but it's not by any means a complete solution (doesn't even contemplate the "Wrong Password" message problem, for example).

mysqlauthz.hg session.hg

Thoughts?

No, I've moved to 1.6... hadn't noticed auth.py moving. Was that a recent thing?

-- NickPhillips

MoinMoin: MoinDev/MoinAuth (last edited 2007-10-29 19:06:12 by localhost)