Bug #44684

Authorization header redirect in .htaccess strips the Basic-prefix

Added by Peter Rauber almost 9 years ago. Updated over 7 years ago.

Status:
New
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2013-01-21
Due date:
% Done:

0%

Estimated time:

Description

The .htaccess file in the web folder contains this command:
SetEnvIfNoCase Authorization "Basic ([a-zA-Z0-9\+/=]+)" REMOTE_AUTHORIZATION=$1

This will strip the prefix "Basic " from the authorization header.

Changing this to:
SetEnvIfNoCase Authorization "Basic ([a-zA-Z0-9\+/=]+)" REMOTE_AUTHORIZATION=$0

worked for me. Maybe this should be updated in the shipped .htaccess-File.

Also available in: Atom PDF