I use spring 5 in all my projects.
I want to add a basic auth with only one secret/login for one endpoint.
(just for remember, a basic auth is based on request who use to authentify an header "Authorization : Basic ${encryptedInBase64('login:password')}")
My issue is, the basic auth initialized by spring-web encrypt the login:secret using a base64 encoder
BUT
spring security don't propose anymore base64 password encoder anymore "because the encryption level is too low"
A quick fix would be
- use the deprecated Md4PasswordEncoder, who encode/decode in base64
- implement my own "MtBase64PasswordEncoder" class, who do the same.
But neither of them seems clean.
So my question is : what is the clean way to do a connection with a basic auth between two spring 5 projects? How does spring expect us to do basic auth?