سؤال

I understand htpasswd is pretty secure if done through SSL. Question:

I visit directory "mysite.com/protected/" (https) and log in via htaccess/htpasswd. In the same browser I open up a new tab to "mysite.com/unprotected/" (http).

Is the user/pass transmitted in the second request, or only when accessing the /protected/ directory?

هل كانت مفيدة؟

المحلول

The user's name and password will be sent with every HTTP request under the protected directory. The user will only be asked (usually) on the first try until you close and reopen the browser.

Here is a good overview.

مرخصة بموجب: CC-BY-SA مع الإسناد
لا تنتمي إلى StackOverflow
scroll top