Missing WWW-Authenticate header in 401 responses
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 58/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- go
- Domain
- api, authentication
Research direction
Start by locating the rest-server request path that produces 401 Unauthorized responses and inspect how its response headers are set. Reproduce the request with wget, add coverage for the WWW-Authenticate header if the project has nearby HTTP tests, and verify that 401 responses include the required challenge header.
Written by the indexing model from the issue text.
Description
Output of rest-server --version
rest-server version rest-server 0.12.1 compiled with go1.20.5 on linux/arm64
Problem description / Steps to reproduce
dwight@chadwick:~ $ wget --user=dwight --ask-password http://<snip>:<snip>/config
Password for user ‘dwight’:
--2025-12-11 17:23:39-- http://<snip>:<snip>/config
Resolving <snip> (<snip>)... <snip>
Connecting to <snip> (<snip>)|<snip>|:<snip>... connected.
HTTP request sent, awaiting response... 401 Unauthorized
Unknown authentication scheme.
Username/Password Authentication Failed.
Note the unknown authentication scheme.
Expected behavior
Per the HTTP spec, the 401 response should include a WWW-Authenticate header. This facilitates a challenge-response flow to negotiate authentication.
Actual behavior
dwight@chadwick:~ $ wget -S http://<snip>:<snip>/config
--2025-12-11 17:21:32-- http://<snip>:<snip>/config
Resolving volta.cinnamon-snake.ts.net (volta.cinnamon-snake.ts.net)... <snip>
Connecting to <snip> (<snip>)|<snip>|:<snip>... connected.
HTTP request sent, awaiting response...
HTTP/1.1 401 Unauthorized
Content-Type: text/plain; charset=utf-8
X-Content-Type-Options: nosniff
Date: Thu, 11 Dec 2025 17:21:33 GMT
Content-Length: 13
Username/Password Authentication Failed.
Note the lack of a WWW-Authenticate response header.
Do you have any idea what may have caused this?
No.
Did rest-server help you today? Did it make you happy in any way?
rest-server is a great compliment to restic and an essential component in my backup solution.
- Dominant language
- Go
- Stars
- 1.5k
- Forks
- 179
- Avg merge
- 15d 9h
- Merged PRs (30d)
- 2
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from restic/rest-server
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
restic/rest-server#389 ·
-
state: need feedback
Difficulty 3/5 1-2 days Newbie friendliness 55/100
restic/rest-server#391 · 5 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
restic/rest-server#390 · 1 comment · 1 reaction ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
restic/rest-server#384 · 2 comments ·
-
Exit after configurable idle period for servers with limited RAM or are off/suspended when unusedOpen
Difficulty 4/5 3-5 days Newbie friendliness 50/100
restic/rest-server#383 · 2 comments ·
All issues in restic/rest-server
Similar issues
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 92/100
open-telemetry/opentelemetry-go-compile-instrumentation#1417 ·
Maintainers usually reply within 2 days
-
agent-research-finding agent-research-recommend chore ready-for-agent
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
jordansmall/spindrift#4068 · 1 comment ·
Maintainers usually reply within 1 day
-
Type/Task
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
OpenNSW/nsw-srilanka#537 ·
Maintainers usually reply within 1 day
-
security
Difficulty 2/5 1-2 days Newbie friendliness 62/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
Maintainers usually reply within 1 day