HTTP Authentication Extensions for Interactive Clients, January 2017
- File formats:
- Y. Oiwa
- httpauth (sec)
Discuss this RFC: Send questions or comments to the mailing list firstname.lastname@example.org
This document specifies extensions for the HTTP authentication framework for interactive clients. Currently, fundamental features of HTTP-level authentication are insufficient for complex requirements of various Web-based applications. This forces these applications to implement their own authentication frameworks by means such as HTML forms, which becomes one of the hurdles against introducing secure authentication mechanisms handled jointly by servers and user agents. The extended framework fills gaps between Web application requirements and HTTP authentication provisions to solve the above problems, while maintaining compatibility with existing Web and non-Web uses of HTTP authentication.
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 8729.