Re: [squid-users] Changing HTTP BASIC 'Realm' to force user logout / reauthentication

From: Henrik Nordstrom <henrik_at_henriknordstrom.net>
Date: Wed, 22 Jul 2009 11:59:29 +0200

tis 2009-07-21 klockan 10:15 +0200 skrev David (Dave) Donnan:

> Background:
>
> http://httpd.apache.org/docs/1.3/howto/auth.html
>
> so that if other resources are requested *from the same realm*, the
> same username and password can be returned to authenticate

Yes..

> However, I surf seamlessly without the HTTP BASIC prompt.

Because the browser doesn't notice. It continues sending the cached
login in each request, and as it's never denied it never sees the change
in realm..

> Should this not work ?

It works in some if you first deny access to notify the browser about
the realm change. But I have no good advice on how to implement that in
Squid without also causing immediate logout request on the first login.

Regards
Henrik
Received on Wed Jul 22 2009 - 09:59:35 MDT

This archive was generated by hypermail 2.2.0 : Wed Jul 22 2009 - 12:00:05 MDT