3 ms·
Right - there is no way for the server to tell a browser to stop sending basic auth credentials.
by nmadden 6y ago
Right - there is no way for the server to tell a browser to stop sending basic auth credentials.
- JosefAssad 6y agoWell, not explicitly. But you can respond with a set-cookie header for the same session id, with an expiry in the past. Browsers will purge expired cookies.
- nmadden 6y agoFor cookies... not for Basic Auth.