Solution is probably to use Digest instead of the Basic authentication method.

Comments

decafdennis’s picture

Title: Work nicely with multiple authentication realms » Implement Digest authentication

...in order to work nicely with multiple authentication realms.

decafdennis’s picture

...and in order to solve #97931.

decafdennis’s picture

Status: Active » Closed (won't fix)

Just reading about Digest authentication and apparently it requires a plain-text password, or a MD5 hash of the password with the username and realm attached, in order to be able to negotiate with the client. Heh, that [verb meaning not very nice]. Stupid me.

One solution is to make users 'enable' digest authentication for their account by specifying their password... bad idea.

Setting this to won't fix until it is absolutely necessary for something.