An old W3C doc lists 'user' as a valid scheme for the Authorization header and is defined like ...
Authorization: user fred:mypassword
There doesn't seem to be a reference to this in the later RFC2617. Has this been deprecated?
Thanks
Chris
In short, yes.
RFC 2616 makes a number of references to HTTP access authentication by referring to RFC 2617 (e.g. §11 Access Authentication). Only 2 schemes are discussed in both RFCs (Basic and Digest).
A few more schemes are discussed in this post, but the scheme from the W3C site doesn't seem to have been implemented anywhere.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With