http_basic_auth.rdoc

doc/http_basic_auth.rdoc

Documentation for HTTP Basic Auth Feature

The HTTP basic auth feature allows logins using HTTP basic authentication, described in RFC 1945.

In your routing block, you can require HTTP basic authentication via:

rodauth.require_http_basic_auth

If you want to allow HTTP basic authentication but not require it, you can call:

rodauth.http_basic_auth

Be aware that if HTTP basic authentication is used as the login method, Rodauth will persist the login into the session, so HTTP basic authentication is only needed for the first request that loads the authentication information, and not for subsequent requests. It can be

Note that rodauth.logged_in? will call http_basic_auth by default if there is no valid session value, allowing for easier integration into typical Rodauth authentication checks. It is recommended to disable this using logged_in_fallback_to_http_basic_auth? false, and be explicit about HTTP basic authentication using rodauth.http_basic_auth or rodauth.require_http_basic_auth.

Auth Value Methods

http_basic_auth_realm

The realm to return in the WWW-Authenticate header.

logged_in_fallback_to_http_basic_auth?

Whether to have rodauth.logged_in? fallback to calling http_basic_auth if there is no active session. true by default for backwards compatibility, will change to false by default in Rodauth 3.

require_http_basic_auth?

If true, when rodauth.require_login or rodauth.require_authentication is used, return a 401 status page if basic auth has not been provided, instead of redirecting to the login page. If false, rodauth.require_login or rodauth.require_authentication will check for HTTP basic authentication if not already logged in. False by default.