[Zope-PAS] Challengers (and Zope 3)

Lennart Regebro regebro at nuxeo.com
Thu Sep 30 13:18:54 EDT 2004


Mark Hammond wrote:
> My reading of the relevant RFCs implies that it should be possible to have
> the actual login page as the body of the 401 message.

Yes, that should work.

>>So, you might say that one might want to mix protocols. But "we"
>>shouldn't do that, that is, PAS should not try to do that, it gets to
>>complicated. It is instead up to each single challenge-plugin
>>to decide what to do.
> 
> That may well be true for protocols other than header-based
> challenge/response mechansisms - but as the standard explicitly defines c/r
> behaviour, I see no reason not to support it.

I'm not sure what you mean with "that" and "it".


More information about the Zope-PAS mailing list