Tor Browser 8 cannot download images protected by basic auth
TB seems to ignore authentication credentials when trying to download images from .onion sites protected by basic http authorization. The "Authorization: Basic" header is missing, and the site returns 401 Authorization Required.
To reproduce this error:
-
Setup an nginx server with some test dummy config and some login:password pair generated by openssl passwd in htpasswd:
root /var/www/html;
server_name _; location / { auth_basic "closed site"; auth_basic_user_file htpasswd; }
-
Put a test .png or .jpg file into /var/www/html
-
Try to access the file at http://.onion/test.png
-
Enter login and password when prompted - check that the file displays properly.
-
Now try to download the file (Ctrl+S) and get a 401 error.
If the server doesn't provide a text response for the 401 error, TB will simply create an empty file.
Trac:
Username: pf.team