Hacker News new | ask | show | jobs
by justsomedood 2102 days ago
BasicAuth is a plain text header, there is no other way to send it. Are you meaning it should only allow Basic Auth over https and refuse to login over http?