-
Notifications
You must be signed in to change notification settings - Fork 495
Description
In the interests of defense-in-depth, this feature request is for "Digest Auth" on the front end of the server so that the user's password is never sent to the server. This would limit exposure of secrets in the event that a client is tricked into connecting to an inauthentic server, as might happen on a network with a captive portal or transparent proxy, not to mention various attack scenarios. While there are known effective attacks against Digest Auth, it is a significant improvement over Basic Auth. My hope is that this request might focus attention on architecture work that will pave the way to stronger front-end authentication protocols in the future.
Thank you for your kind attention and your contributions to the world of free, open source software.