basic_auth

HTTP Basic Authentication filter (RFC 7617).
On this page

HTTP Basic Authentication filter (RFC 7617).

Requires Cargo feature: basic-auth-filter.

Configuration Notes

Deprecated: slated for removal in favor of the authentication support in the Praxis policy engine (https://github.com/praxis-proxy/policy).

Experimental: requires the basic-auth-filter cargo feature, which is off by default. Credentials are stored in plaintext; this filter is intended for development and testing only.

Extracts credentials from the Authorization: Basic header, validates against a configurable credential source (inline list or runtime KV store), publishes the verified username as an [AuthenticatedIdentity], and returns 401 with WWW-Authenticate: Basic realm="..." on failure.

Configuration

FieldTypeRequiredDescription
realmstringnoRealm string for the WWW-Authenticate challenge.
strip_authorizationboolnoWhether to strip the Authorization header before forwarding.
credentialsInlineCredential[]noInline credential list.
credentials[].usernamestringyesUsername for authentication.
credentials[].passwordstringnoLiteral password value.
credentials[].env_varstringnoEnvironment variable containing the password.
kv_storestringnoKV store name for credential lookup.

Example

filter: basic_auth
realm: "Restricted"
strip_authorization: true
credentials:
  - username: admin
    password: secret
  - username: deploy
    env_var: DEPLOY_PASSWORD