• psycotica0@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 days ago

    The return of SASL DIGEST! (Or these days probably CRAM or SCRAM)

    But yeah, the “hard” part would be that you don’t want the user to type in a password to the website because it could get snatched, so you’d want the User Agent to pop up a password prompt, you type it, and then it does the hashing etc internally and only dumps the hash into the request. So you’d still need some kind of standard for that.

    Which is basically just HTTP auth from the 90s. So the good news is that’s always been possible, and already has broad support and works with all browsers! 😛