Allow individual users to opt out of HTTP Digest auth

XMLWordPrintable

    • Type: New Feature
    • Resolution: Fixed
    • Priority: Normal
    • 2026-07-30
    • Affects Version/s: None
    • Component/s: Accounts
    • None
    • Village

      As detailed in MBS-9207, supporting HTTP Digest auth requires the server to store the password in almost-plain format. Until the support for Digest can be removed, we should offer security-conscious users the option not to store an ha1 value (which means that they can’t use Digest auth, but aren’t as vulnerable in case their data should be exposed).

            Assignee:
            Michael Wiencek
            Reporter:
            Ulrich Klauer
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:

                Version Package
                2026-07-30