Well, I'll be looking at that later this year when I port my Pylons
app with a hybrid LDAP+local db users, but I don't have any comment at
this point. I'll consider either repoze.who connected to Pyramid's
auth, or a custom authenticator if that's too messy. I'd have to write
a custom module for repoze.who in any case, and I'm not sure going
through Who's API would be worth the effort. On the other hand, I'
would like to use Who's automatic fallback to Authorized headers
instead of forms for non-interactive user agents.
--
Mike Orr <slugg...@gmail.com>