|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Layer: L6 Presentation ยท Build flags: PROTOCORE_ENABLE_AUTH (on by default)
This is BasicAuth with one change: pass digest=true to the authenticated on() overload and the route is protected with HTTP Digest (RFC 7616, SHA-256, qop="auth") instead of Basic. With Digest the password never crosses the wire - only a salted hash of it does - and unauthenticated requests get a 401 plus a WWW-Authenticate: Digest challenge automatically.
One extra argument. The signature is the same as Basic auth, with a trailing true:
The handler is reached only after the client computes a correct digest response from the server's nonce - so the server never sees, stores, or transmits the password in the clear.
Testing caveat (Windows curl).
curl --digeston Windows routes Digest through SSPI/SChannel, which rejects this SHA-256 /qop="auth"challenge (SEC_E_QOP_NOT_SUPPORTED) and never sends credentials. That is a Windows-curl limitation, not a server bug - the challenge is standard RFC 7616 and works with a browser,wget, or Linux/macOS curl.
The complete sketch (DigestAuth.ino), reproduced verbatim with added explanatory comments: