[ https://issues.apache.org/jira/browse/HTTPCLIENT-1625?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17876633#comment-17876633 ]
Istvan Toth commented on HTTPCLIENT-1625: ----------------------------------------- Reading your replies again: bq. 2. propagates 401status in case of authentication failure (bad credentials) and if necessary populates additional details in the `HttpContext` You mean that if the mutual authentication fails locally, then we should generate a synthetic 401/407 response and return that ? In that case there would be no exception where the real response could be returned. Should we add the real response to the HttpContext ? > Completely overhaul GSS-API-based authentication backend > -------------------------------------------------------- > > Key: HTTPCLIENT-1625 > URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1625 > Project: HttpComponents HttpClient > Issue Type: Task > Components: Documentation, HttpClient (classic) > Affects Versions: 4.5 > Reporter: Michael Osipov > Priority: Major > Labels: stuck, volunteers-wanted > > The current implementation does not reflect the way GSS-API-based > authentication should be done. It has several design flaws. > This is an umbrella task for: > 1. Deprecate all old classes > 2. Investigate how it has to be plugged into HttpClient > 3. Reimplement from scratch > 4. Thoroughly test all new stuff > 5. Rewrite documentation > Design notes are canonically available under: > https://wiki.apache.org/HttpComponents/IssueTracking/HTTPCLIENT-1625 -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@hc.apache.org For additional commands, e-mail: dev-h...@hc.apache.org