Thanks for reading my mind.  I _DID_ intend to say "preauth
filter" and not "trace filters" -- that's what I get for
trying to use my branes on a Monday.

-- Dossy
BRANES!


On 2002.04.09, Rob Mayoff <[EMAIL PROTECTED]> wrote:
> +---------- On Apr 9, Zoran Vasiljevic said:
> > On Monday 08 April 2002 22:04, Dossy wrote:
> >
> > >
> > > Could auth schemes not be implemented via trace filters?
> > >
> >
> > Well, almost...
>
> Actually, it's can't.  A trace filter runs after the main request
> handler - too late to block access.
>
> A preauth or postauth filter can perform authorization. It will have to
> parse the Authorization header itself. If the client is not authorized,
> then the filter must send a 401 response with a WWW-Authenticate header,
> and return "filter_return".  If the client is authorized, the filter
> should just return "filter_ok" (and not send anything to the client).
>
> If you load ns_perm, then it will also attempt to authorize requests.
> The simplest solution is to not load ns_perm. If you do load ns_perm,
> then (I think) you may simply tell it to allow user "" to access any
> URLs that are otherwise protected by your Digest filter. Here's how.
>
> Make sure this line is in nsperm's passwd file:
>
>     ""::::::
>
> (It is already in the default passwd file.)  Then put this line in the
> perms file:
>
>     allowuser inherit GET /my/digest-protected/url ""
>
> Substitute the appropriate URL in place of "/my/digest-protected/url".
> Repeat with different URLs as required.

--
Dossy Shiobara                       mail: [EMAIL PROTECTED]
Panoptic Computer Network             web: http://www.panoptic.com/
  "He realized the fastest way to change is to laugh at your own
    folly -- then you can let go and quickly move on." (p. 70)

Reply via email to