aboutsummaryrefslogtreecommitdiff
path: root/doc/bugs/anonok_vs._httpauth.mdwn
diff options
context:
space:
mode:
authorJoey Hess <joey@gnu.kitenet.net>2010-01-04 19:51:37 -0500
committerJoey Hess <joey@gnu.kitenet.net>2010-01-04 19:51:37 -0500
commit2a717f36ef89d062a359813cdebb2f2e30e4343e (patch)
treefb14d4e299f48b25c9285018aaca8de0e2579d8f /doc/bugs/anonok_vs._httpauth.mdwn
parent264f46989470db93293938e327744554b5177f82 (diff)
downloadikiwiki-2a717f36ef89d062a359813cdebb2f2e30e4343e.tar
ikiwiki-2a717f36ef89d062a359813cdebb2f2e30e4343e.tar.gz
response
Diffstat (limited to 'doc/bugs/anonok_vs._httpauth.mdwn')
-rw-r--r--doc/bugs/anonok_vs._httpauth.mdwn10
1 files changed, 10 insertions, 0 deletions
diff --git a/doc/bugs/anonok_vs._httpauth.mdwn b/doc/bugs/anonok_vs._httpauth.mdwn
index 688274d67..0015627b0 100644
--- a/doc/bugs/anonok_vs._httpauth.mdwn
+++ b/doc/bugs/anonok_vs._httpauth.mdwn
@@ -24,3 +24,13 @@ and a whitelist of OpenIDs in `locked_pages`...)
>> the current page can be edited by the current user (if any)? What
>> if there were a way to require particular auth plugins for particular
>> PageSpecs? --[[schmonz]]
+
+>>> The decision about whether a user can edit a page is made by plugins
+>>> such as signinedit and lockedit, that also use canedit hooks to redirect
+>>> the user to a signin page if necessary.
+>>>
+>>> A tweak on my earlier suggestion would be to have httpauth notice when the
+>>> Signin page is being built and immediatly redirect to the cgiauthurl
+>>> before the page can be shown to the user. This would, though, not play
+>>> well with other authentication methods like openid, since the user
+>>> would never see the Signin form. --[[Joey]]