Double password query with SSL

The following scenario always results in an undesirable side effect: If you protect your site with htaccess/htpasswd and simultaneously enforce an SSL connection, you always have to enter the same password twice (once for http and again for https after successful entry). This problem can be easily solved using the configuration sections introduced in Apache 2.4.


# SSL erzwingen
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

# Authentifizierung (nur bei verschlüsselten Verbindungen)
<If "%{HTTPS} == 'on'">
AuthUserFile /path/to/.htpasswd
AuthName "Interner Bereich"
AuthType Basic
require valid-user
</If>
Back