Digest Access Authentication

After but five minutes of perusal, I have these comments:

1) Section 2.1 says the headers must be on one line.  This contradicts
the current HTTP spec., which allows continuation if the following line
begins with whitespace.

2) I would like to suggest an optional "prompt" attribute whose default
value is the same as the "realm" attribute.  To my way of thinking, the
"realm" is a short-hand name the server uses to identify the realm,
whereas "prompt" would be what the server would like the user to know
about the realm when s/he is prompted for name/password.

Nit:  last sentence of section 1.1:  "... be included in the the proposed...".
(Double "the".)

Dave Kristol

Received on Tuesday, 14 March 1995 15:51:22 UTC