From: Kent Sibilev Date: 2005-02-09T09:41:41+09:00 Subject: Re: HTTP Basic authentication for open_uri Tanaka Akira writes: > In article <6306120cc60ccc430b841596e52c3e91@bellsouth.net>, > Kent Sibilev writes: > >> That enables the following usage: >> >> open('http://user:pwd@homename') do |f| >> ... >> end > > Since the format is deprecated, open-uri doesn't support the format. > > RFC 3986: > > Use of the format "user:password" in the userinfo field is > deprecated. Applications should not render as clear text any data > after the first colon (":") character found within a userinfo > subcomponent unless the data after the colon is the empty string > (indicating no password). Applications may choose to ignore or > reject such data when it is received as part of a reference and > should reject the storage of such data in unencrypted form. The > passing of authentication information in clear text has proven to be > a security risk in almost every case where it has been used. > -- > Tanaka Akira OK, I didn't know about it. In this case, should it still provide a little bit more user-friendly API anyway? Something like: open("http://www.example.com", :auth_info => [user, pwd]) do |f| ... end Cheers, Kent.