32 messages in com.googlegroups.pylons-discussRe: Auth and Auth
FromSent OnAttachments
Yannick Gingras27 Mar 2008 07:44 
Ian Bicking27 Mar 2008 09:01 
Wolverine27 Mar 2008 09:42 
Eric Ongerth27 Mar 2008 19:56 
Dalius Dobravolskas27 Mar 2008 23:01 
Dalius Dobravolskas27 Mar 2008 23:42 
chrism28 Mar 2008 09:38 
chrism28 Mar 2008 10:07 
Chris AtLee28 Mar 2008 11:04 
Mike Orr28 Mar 2008 13:48 
Ian Bicking28 Mar 2008 14:55 
Jorge Vargas28 Mar 2008 21:12 
Mike Orr28 Mar 2008 22:19 
Wichert Akkerman29 Mar 2008 03:44 
lasizoillo29 Mar 2008 07:50 
Dalius Dobravolskas29 Mar 2008 10:16 
Dalius Dobravolskas29 Mar 2008 10:27 
Dalius Dobravolskas29 Mar 2008 10:29 
Dalius Dobravolskas29 Mar 2008 10:35 
mdoudoroff29 Mar 2008 16:23 
Mike Orr29 Mar 2008 20:36 
Ian Bicking30 Mar 2008 11:56 
Ross Vandegrift30 Mar 2008 12:05 
Ross Vandegrift30 Mar 2008 12:08 
Dalius Dobravolskas30 Mar 2008 22:36 
Dalius Dobravolskas31 Mar 2008 04:21 
Chris Shenton31 Mar 2008 08:24 
Mike Orr31 Mar 2008 11:16 
Dalius Dobravolskas01 Apr 2008 13:16 
Ian Bicking01 Apr 2008 13:58 
johnnyice16 Apr 2008 08:38 
Eric Ongerth16 Apr 2008 18:27 
Subject:Re: Auth and Auth
From:Wichert Akkerman (wich@public.gmane.org)
Date:03/29/2008 03:44:25 AM
List:com.googlegroups.pylons-discuss

Previously Mike Orr wrote:

AuthKit's author James Gardner says the architecture is sound, the outstanding bugs have been fixed, and the two substantial chapters in the Pylons Book space on the wiki have been audited for Pylons 0.9.6. Against this are 4-5 people on IRC and this list who have had bad experiences with AuthKit and think it should be thrown into the ocean. Their argument seems to be not that it doesn't work (the previous bugs have been fixed), but that you can write your own authentication in the time it takes to learn it.

There is an important lesson here: a very important, if not the most important, factor for adaption of a tool such as AuthKit is the quality of its documentation and how easy it is for complete newcomers to start using it. I consider myself a reasonably experienced programmer and I found myself overwhelmed by the complexity of the AuthKit documentation and setup. If there was a single tutorial that said 'do A and B and voila! your app is now protected' AuthKit would probably be much more accepted. Instead there are two pages in the pylons book that try to cover all of AuthKit, which means they introduce so much complexity that my first response was 'my needs are very simple, I will look elsewhere'. After actually using AuthKit since there were no good alternatives at the time and I did not want to bother to write my own thing I still think that.

Wichert.