Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Missing WWW-Authenticate header in 401 responses

Open
#376 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
58/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
go

Research direction

Start by locating the rest-server request path that produces 401 Unauthorized responses and inspect how its response headers are set. Reproduce the request with wget, add coverage for the WWW-Authenticate header if the project has nearby HTTP tests, and verify that 401 responses include the required challenge header.

Written by the indexing model from the issue text.

Description

Output of rest-server --version

rest-server version rest-server 0.12.1 compiled with go1.20.5 on linux/arm64

Problem description / Steps to reproduce

dwight@chadwick:~ $ wget --user=dwight --ask-password http://<snip>:<snip>/config
Password for user ‘dwight’:
--2025-12-11 17:23:39--  http://<snip>:<snip>/config
Resolving <snip> (<snip>)... <snip>
Connecting to <snip> (<snip>)|<snip>|:<snip>... connected.
HTTP request sent, awaiting response... 401 Unauthorized
Unknown authentication scheme.

Username/Password Authentication Failed.

Note the unknown authentication scheme.

Expected behavior

Per the HTTP spec, the 401 response should include a WWW-Authenticate header. This facilitates a challenge-response flow to negotiate authentication.

Actual behavior

dwight@chadwick:~ $ wget -S http://<snip>:<snip>/config
--2025-12-11 17:21:32--  http://<snip>:<snip>/config
Resolving volta.cinnamon-snake.ts.net (volta.cinnamon-snake.ts.net)... <snip>
Connecting to <snip> (<snip>)|<snip>|:<snip>... connected.
HTTP request sent, awaiting response...
  HTTP/1.1 401 Unauthorized
  Content-Type: text/plain; charset=utf-8
  X-Content-Type-Options: nosniff
  Date: Thu, 11 Dec 2025 17:21:33 GMT
  Content-Length: 13

Username/Password Authentication Failed.

Note the lack of a WWW-Authenticate response header.

Do you have any idea what may have caused this?

No.

Did rest-server help you today? Did it make you happy in any way?

rest-server is a great compliment to restic and an essential component in my backup solution.

Dominant language
Go
Stars
1.5k
Forks
179
Avg merge
15d 9h
Merged PRs (30d)
2

Getting set up

  • Ships a Dockerfile or Docker Compose file
  • Has a pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from restic/rest-server

All issues in restic/rest-server

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.