basic_auth
HTTP Basic Authentication filter (RFC 7617).
On this page
HTTP Basic Authentication filter (RFC 7617).
Requires Cargo feature: basic-auth-filter.
Configuration Notes
Deprecated: slated for removal in favor of the authentication support in the Praxis policy engine (https://github.com/praxis-proxy/policy).
Experimental: requires the basic-auth-filter cargo feature, which is off by default. Credentials are stored in plaintext; this filter is intended for development and testing only.
Extracts credentials from the Authorization: Basic header, validates against a configurable credential source (inline list or runtime KV store), publishes the verified username as an [AuthenticatedIdentity], and returns 401 with WWW-Authenticate: Basic realm="..." on failure.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
realm | string | no | Realm string for the WWW-Authenticate challenge. |
strip_authorization | bool | no | Whether to strip the Authorization header before forwarding. |
credentials | InlineCredential[] | no | Inline credential list. |
credentials[].username | string | yes | Username for authentication. |
credentials[].password | string | no | Literal password value. |
credentials[].env_var | string | no | Environment variable containing the password. |
kv_store | string | no | KV store name for credential lookup. |
Example
filter: basic_auth
realm: "Restricted"
strip_authorization: true
credentials:
- username: admin
password: secret
- username: deploy
env_var: DEPLOY_PASSWORD