new test: repeated request to a URL that previously required HTTP authentication
diff --git a/XMLHttpRequest/send-authentication-basic-repeat-no-args.htm b/XMLHttpRequest/send-authentication-basic-repeat-no-args.htm new file mode 100644 index 0000000..6ae1ce4 --- /dev/null +++ b/XMLHttpRequest/send-authentication-basic-repeat-no-args.htm
@@ -0,0 +1,31 @@ +<!doctype html> +<html> + <head> + <title>XMLHttpRequest: send() - "Basic" authenticated requests with user name and password passed to open() in first request, without in second</title> + <script src="/resources/testharness.js"></script> + <script src="/resources/testharnessreport.js"></script> + <link rel="help" href="http://dvcs.w3.org/hg/xhr/raw-file/tip/Overview.html#the-open()-method" data-tested-assertations="following::ol[1]/li[9]/ol[1]/li[1] following::ol[1]/li[9]/ol[1]/li[2]" /> + <link rel="help" href="http://dvcs.w3.org/hg/xhr/raw-file/tip/Overview.html#the-send()-method" data-tested-assertations="following::code[contains(@title,'http-authorization')]/.." /> + </head> + <body> + <div id="log"></div> + <script> + test(function() { + var client = new XMLHttpRequest(), + urlstart = location.host + location.pathname.replace(/\/[^\/]*$/, '/') + client.open("GET", location.protocol+'//'+urlstart + "resources/auth1/auth.php", false, 'user', 'pass') + client.setRequestHeader("x-user", 'user') + client.setRequestHeader("x-pass", 'pass') + client.send(null) + // Repeat request but *without* credentials in the open() call. + // Is the UA supposed to cache credentials from above request and use them? Yes. + client.open("GET", location.protocol+'//'+urlstart + "resources/auth1/auth.php", false) + client.send(null) + + assert_equals(client.responseText, 'user' + "\n" + 'pass') + assert_equals(client.getResponseHeader('x-challenge'), 'DID-NOT') + + }, document.title) + </script> + </body> +</html>