Re: HTTP Basic Auth

Alexander Lukyanov <[email protected]> Wed, 3 Jul 2019 13:13:15 +0300
Newsgroups gmane.network.lftp.user
Message-ID <CANnoEwo8ikMrcnGYLJqdDssE1sM8xvGnVKHU04w1PoUm6Vu=2A@mail.gmail.com>
--===============4546856196291325708==
Content-Type: multipart/alternative; boundary="000000000000adbd66058cc41ce6"

--000000000000adbd66058cc41ce6
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Lftp started to support digest authentication, so it sends an
unauthenticated request first to get a challenge.
It should be possible to add a setting to choose auth methods, so that when
only basic method is enabled, then skip the initial unauthenticated
request.

=D1=87=D1=82, 16 =D0=BC=D0=B0=D1=8F 2019, 20:58 Nate Sutton <[email protected]=
>:

> Something changed between lftp 4.4.8 and lftp 4.8.4 with HTTP basic auth.
> In the newer version it only sends the Authorization header if it receive=
s
> a challenge response from making a request without the header. In the old=
er
> version it always sent the Authorization header.
>
> Is there a way to force sending the Authorization header on the first
> request? Not all endpoints that accept HTTP basic auth respond with a
> challenge, some redirect to oauth or whatever else.
>
> Thanks!
> _______________________________________________
> lftp mailing list
> [email protected]
> http://univ.uniyar.ac.ru/mailman/listinfo/lftp
>

--000000000000adbd66058cc41ce6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Lftp started to support digest authentication, so it send=
s an unauthenticated request first to get a challenge.=C2=A0<div dir=3D"aut=
o">It should be possible to add a setting to choose auth methods, so that w=
hen only basic method is enabled, then skip the initial unauthenticated req=
uest.=C2=A0</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" clas=
s=3D"gmail_attr">=D1=87=D1=82, 16 =D0=BC=D0=B0=D1=8F 2019, 20:58 Nate Sutto=
n &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt;:<br></div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px =
#ccc solid;padding-left:1ex"><div dir=3D"ltr">Something changed between lft=
p 4.4.8 and lftp 4.8.4 with HTTP basic auth. In the newer version it only s=
ends the Authorization header if it receives a challenge response from maki=
ng a request without the header. In the older version it always sent the Au=
thorization header.<div><br></div><div>Is there a way to force sending the =
Authorization header on the first request? Not all endpoints that accept HT=
TP basic auth respond with a challenge, some redirect to oauth or whatever =
else.</div><div><br></div><div>Thanks!</div></div>
_______________________________________________<br>
lftp mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">l=
[email protected]</a><br>
<a href=3D"http://univ.uniyar.ac.ru/mailman/listinfo/lftp" rel=3D"noreferre=
r noreferrer" target=3D"_blank">http://univ.uniyar.ac.ru/mailman/listinfo/l=
ftp</a><br>
</blockquote></div>

--000000000000adbd66058cc41ce6--

--===============4546856196291325708==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lftp mailing list
[email protected]
http://univ.uniyar.ac.ru/mailman/listinfo/lftp

--===============4546856196291325708==--