I see there are a few. Which ones are maintained and easy to use? What are their pros and cons?
Share
Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.
Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.
Lost your password? Please enter your email address. You will receive a link and will create a new password via email.
Please briefly explain why you feel this question should be reported.
Please briefly explain why you feel this answer should be reported.
Please briefly explain why you feel this user should be reported.
Update (May 14, 2010):
It turns out, the russian developer Ilya Konyukhov picked up the gauntlet after reading this and created a new auth library for CI based on DX Auth, following the recommendations and requirements below.
And the resulting Tank Auth is looking like the answer to the OP’s question. I’m going to go out on a limb here and call Tank Auth the best authentication library for CodeIgniter available today. It’s a rock-solid library that has all the features you need and none of the bloat you don’t:
Tank Auth
Download Tank Auth here
Original answer:
I’ve implemented my own as well (currently about 80% done after a few weeks of work). I tried all of the others first; FreakAuth Light, DX Auth, Redux, SimpleLogin, SimpleLoginSecure, pc_user, Fresh Powered, and a few more. None of them were up to par, IMO, either they were lacking basic features, inherently INsecure, or too bloated for my taste.
Actually, I did a detailed roundup of all the authentication libraries for CodeIgniter when I was testing them out (just after New Year’s). FWIW, I’ll share it with you:
DX Auth
FreakAuth Light
pc_user
Fresh Powered
Redux / Ion Auth
According to the CodeIgniter wiki, Redux has been discontinued, but the Ion Auth fork is going strong: https://github.com/benedmunds/CodeIgniter-Ion-Auth
Ion Auth is a well featured library without it being overly heavy or under advanced. In most cases its feature set will more than cater for a project’s requirements.
SimpleLoginSecure
Don’t get me wrong: I don’t mean to disrespect any of the above libraries; I am very impressed with what their developers have accomplished and how far each of them have come, and I’m not above reusing some of their code to build my own. What I’m saying is, sometimes in these projects, the focus shifts from the essential ‘need-to-haves’ (such as hard security practices) over to softer ‘nice-to-haves’, and that’s what I hope to remedy.
Therefore: back to basics.
Authentication for CodeIgniter done right
Here’s my MINIMAL required list of features from an authentication library. It also happens to be a subset of my own library’s feature list 😉
Note: those last few points are not super-high-security overkill that you don’t need for your web application. If an authentication library doesn’t meet these security standards 100%, DO NOT USE IT!
Recent high-profile examples of irresponsible coders who left them out of their software: #17 is how Sarah Palin’s AOL email was hacked during the Presidential campaign; a nasty combination of #18 and #19 were the culprit recently when the Twitter accounts of Britney Spears, Barack Obama, Fox News and others were hacked; and #20 alone is how Chinese hackers managed to steal 9 million items of personal information from more than 70.000 Korean web sites in one automated hack in 2008.
These attacks are not brain surgery. If you leave your back doors wide open, you shouldn’t delude yourself into a false sense of security by bolting the front. Moreover, if you’re serious enough about coding to choose a best-practices framework like CodeIgniter, you owe it to yourself to at least get the most basic security measures done right.
<rant>
Basically, here’s how it is: I don’t care if an auth library offers a bunch of features, advanced role management, PHP4 compatibility, pretty CAPTCHA fonts, country tables, complete admin panels, bells and whistles — if the library actually makes my site less secure by not following best practices. It’s an authentication package; it needs to do ONE thing right: Authentication. If it fails to do that, it’s actually doing more harm than good.
</rant>
/Jens Roland