Re: Kronolith / sabredav: No basic authentication headers found

Michael J Rubinsky <[email protected]>
Newsgroups gmane.comp.horde.kronolith
Message-ID <20150512100413.Horde.LJUYAsq7nNLmpwQSIuJzgPL@h4.theupstairsroom.com>
Quoting [email protected]:

> Zitat von Jan Schneider <[email protected]>:
>
>> Zitat von [email protected]:
>>
>>> Zitat von Jan Schneider <[email protected]>:
>>>
>>>> Zitat von [email protected]:
>>>>
>>>>> Zitat von [email protected]:
>>>>>
>>>>>> Hello,
>>>>>>
>>>>>> we use Horde/Kronolith for CalDAV calender access from multiple  
>>>>>> clients. In a network trace we can see that Horde refuses  
>>>>>> CalDAV access with cookies set with Sabre DAV Exception and "No  
>>>>>> basic authentication headers found". This lead to  
>>>>>> http://tuxd00d.com/blog/sabredav-no-basic-authentication-headers-were-found/ but the problem is said to occur only with CGI/FastCGI which we don't use. We have Ubuntu 12.04 with Apache and PHP5 as module with the latest Horde/Kronolith and all other is working fine. Any idea how to debug/solve  
>>>>>> this?
>>>>>>
>>>>>> Thanks
>>>>>>
>>>>>> Andreas
>>>>>
>>>>> Hm, found this in horde/.htaccess
>>>>>
>>>>> # IMPORTANT: DO NOT EDIT THIS FILE!
>>>>> # It will be overwritten with any future upgrade.
>>>>>
>>>>> allow from all
>>>>>
>>>>> <IfModule mod_rewrite.c>
>>>>> RewriteEngine On
>>>>> RewriteRule .* - [env=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
>>>>> RewriteCond   %{REQUEST_FILENAME}  !-d
>>>>> RewriteCond   %{REQUEST_FILENAME}  !-f
>>>>> RewriteRule ^(.*)$ rampage.php [QSA,L]
>>>>> </IfModule>
>>>>>
>>>>>
>>>>> so the missing header should not be the problem, no?
>>>>>
>>>>> Ayn idea how to solve this? We have slow access because of  
>>>>> additional round trips and hundreds of unused sessions on the  
>>>>> server because of constant re-authentication.
>>>>
>>>> And *are* the headers actually missing, i.e. can those client not  
>>>> authenticate at all?
>>>>
>>>
>>> In fact they can authenticate, but they have to authenticate at  
>>> every request because the cookie ist not accepted. So we have a  
>>> constant re-authentication without session reuse :-(
>>
>> This is how CalDAV works. Or almost any REST API based on HTTP  
>> authentication.
>
> Hm, ok. This lead to further questions:
>
> - Why does Horde create a (expansive) session for CalDAV calls and  
> reply with a session cookie included if it is not used at all?
>
> - How to get a decent performance without doing full blown  
> authentication/session creation on every request on the server?
>
> We will start using CalDAV for a couple of users but with a single  
> Testuser doing CalDAV sync we get some hundred useless sessions on  
> the horde server already and the poor client is trying to use the  
> provided cookie on every request only to repeat it afterwards  
> because of "401 Unauthorized" reply.
>
> This could not be the way it is intended to work, no?

If CalDAV requests are truly stateless we should use probably be using  
the null session driver (session_control = 'none') for those requests.


-- 
mike
The Horde Project
http://www.horde.org
https://www.facebook.com/hordeproject
https://www.twitter.com/hordeproject

-- 
kronolith mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: [email protected]
smime.p7s (application/pkcs7-signature, 5.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.