On 1 Feb 2014, at 05:03, Andy Bradford <amb-fos...@bradfords.org> wrote:

> If everyone else agrees that this  is a good idea (automatically sending
> HTTP Authorization  in response  to 401)

How does fossil authenticate with a server, does it send the password 
plaintext? HTTP Basic Auth does!

I'm not sure whether this should just happen by default unless the connection 
is HTTPS as defaulting to sending plaintext auth data over HTTP seems like a 
bad idea.

Also I never knew about prefixing the password with #, for me documenting that 
is enough. I'm happy now using it as is.

Thanks,
Kevin
_______________________________________________
fossil-users mailing list
fossil-users@lists.fossil-scm.org
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

Reply via email to