Digest Access Authentication

Dave Kristol (dmk@allegra.att.com)
Tue, 14 Mar 95 18:28:44 EST


After but five minutes of perusal, I have these comments:

1) Section 2.1 says the headers must be on one line.  This contradicts
the current HTTP spec., which allows continuation if the following line
begins with whitespace.

2) I would like to suggest an optional "prompt" attribute whose default
value is the same as the "realm" attribute.  To my way of thinking, the
"realm" is a short-hand name the server uses to identify the realm,
whereas "prompt" would be what the server would like the user to know
about the realm when s/he is prompted for name/password.

Nit:  last sentence of section 1.1:  "... be included in the the proposed...".
(Double "the".)

Dave Kristol