From: James Edward Gray II Date: 2010-09-27T10:57:43+09:00 Subject: [ruby-core:32578] Re: [Ruby-Feature#3848][Open] Using http basic authentication for FTP with Open URI On Sep 26, 2010, at 8:44 PM, mathew wrote: > On Sat, Sep 18, 2010 at 13:19, James Edward Gray II > wrote: >> OpenURI is just a wrapper around some clever URI parsing and URI seems to support it just fine: >> >>>> require "uri" >> => true >>>> u = URI.parse("http://user:pass@server.com/") >> => # >>>> u.userinfo >> => "user:pass" >>>> u.host >> => "server.com" > > I feel obliged to point out that this is deprecated by the current > generic URI RFC. > > RFC3986 section 3.2.1: 'Use of the format "user:password" in the > userinfo field is deprecated.' > > RFC2396 stated that it was "NOT RECOMMENDED". > > RFC1738 didn't allow it at all. > > So building systems which store and process username and password in > this way is a bad idea. I'm not sure that really applies to open-uri's usage of this strategy. It's just a familiar interface, not some attempt to correctly mirror how FTP servers manage logins. Does that make sense? James Edward Gray II