Basic Authentication

Basic Authentication and htpasswd in a Directory

In Basic authentication (RFC 7617) the server answers 401 with a realm, and the browser shows a login dialog, then sends user:password in Base64 on every request to that realm. sudo htpasswd -c -B -C 12 /etc/apache2/auth/htpasswd alice creates the file, prompting twice; -c overwrites an existing file, so omit it for later users. -B -C 12 means bcrypt at cost 12.

Password-protecting a directoryApache config
# /var/www/example/admin/.htaccess - Needs: AllowOverride AuthConfig
AuthType Basic
AuthName "Staff area"
AuthBasicProvider file
AuthUserFile /etc/apache2/auth/htpasswd
Require valid-user

Line 2 selects mod_auth_basic. Line 3 is the realm; directories sharing an AuthName share one cached login. Line 4 is the default lookup (dbm and dbd, a SQL query, are the others), line 5 takes an absolute path, and line 6 admits anyone in the file.

No password, a wrong one, a right one, and what travels on the wireShell
curl -si localhost:8108/admin/ | grep -E '^(HTTP|WWW)'
curl -s -o /dev/null -w '%{http_code}\n' -u alice:wrong localhost:8108/admin/
curl -s -o /dev/null -w '%{http_code}\n' -u 'alice:Tr0ub4dor&3' localhost:8108/admin/
curl -sv -u 'alice:Tr0ub4dor&3' localhost:8108/admin/ 2>&1 | grep -o 'Authorization: .*'
echo YWxpY2U6VHIwdWI0ZG9yJjM= | base64 -d; echo
Output
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Basic realm="Staff area"
401
200
Authorization: Basic YWxpY2U6VHIwdWI0ZG9yJjM=
alice:Tr0ub4dor&3

The wrong password logged AH01617: ... Password Mismatch. Base64 is not encryption, so use Basic authentication over HTTPS only (HTTPS and HSTS). There is no logout, and Digest is no fix: its manual says it "no longer fulfills that design goal".