Title: Daniel Westermann-Clark's Replies | WordPress.org

---

# Daniel Westermann-Clark

  [  ](https://wordpress.org/support/users/dwc/)

 *   [Profile](https://wordpress.org/support/users/dwc/)
 *   [Topics Started](https://wordpress.org/support/users/dwc/topics/)
 *   [Replies Created](https://wordpress.org/support/users/dwc/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/dwc/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/dwc/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/dwc/engagements/)
 *   [Favorites](https://wordpress.org/support/users/dwc/favorites/)

 Search replies:

## Forum Replies Created

Viewing 15 replies - 1 through 15 (of 36 total)

1 [2](https://wordpress.org/support/users/dwc/replies/page/2/?output_format=md) 
[3](https://wordpress.org/support/users/dwc/replies/page/3/?output_format=md) [→](https://wordpress.org/support/users/dwc/replies/page/2/?output_format=md)

 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Network Username Restrictions Override] Quick fix for this plugin.](https://wordpress.org/support/topic/quick-fix-for-this-plugin/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [9 years, 7 months ago](https://wordpress.org/support/topic/quick-fix-for-this-plugin/#post-8769990)
 * I’ve added both [@joraff](https://wordpress.org/support/users/joraff/) and [@shankie](https://wordpress.org/support/users/shankie/)
   as committers per the other threads:
 * * [https://wordpress.org/support/topic/maintained-fork/](https://wordpress.org/support/topic/maintained-fork/)
   *
   [https://wordpress.org/support/topic/allow-access-to-fork-contributors-on-github/](https://wordpress.org/support/topic/allow-access-to-fork-contributors-on-github/)
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Network Username Restrictions Override] Maintained fork](https://wordpress.org/support/topic/maintained-fork/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [9 years, 7 months ago](https://wordpress.org/support/topic/maintained-fork/#post-8769989)
 * I’ve added both [@joraff](https://wordpress.org/support/users/joraff/) and [@shankie](https://wordpress.org/support/users/shankie/)
   as committers.
 * [https://wordpress.org/support/topic/allow-access-to-fork-contributors-on-github/](https://wordpress.org/support/topic/allow-access-to-fork-contributors-on-github/)
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Network Username Restrictions Override] Allow access to fork contributors on Github](https://wordpress.org/support/topic/allow-access-to-fork-contributors-on-github/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [9 years, 7 months ago](https://wordpress.org/support/topic/allow-access-to-fork-contributors-on-github/#post-8748594)
 * I’m more than happy to add new committers to the repository. [@shankie](https://wordpress.org/support/users/shankie/),
   you’re now on the list.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Network Username Restrictions Override] Maintained fork](https://wordpress.org/support/topic/maintained-fork/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [9 years, 12 months ago](https://wordpress.org/support/topic/maintained-fork/#post-8214347)
 * Hi,
 * Thanks for the updates. I’ve added you as a committer for the wordpress.org plugin.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] 500 Internal Server Error](https://wordpress.org/support/topic/500-internal-server-error-234/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 2 months ago](https://wordpress.org/support/topic/500-internal-server-error-234/#post-3922761)
 * Did you check the server error log for details?
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] Forgotten Password Mechanism](https://wordpress.org/support/topic/forgotten-password-mechanism/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 2 months ago](https://wordpress.org/support/topic/forgotten-password-mechanism/#post-3810244)
 * Interesting idea. I think your best option would be to:
    1. Remove your lost password URL from requiring authentication by adjusting your`.
       htaccess`.
    2. Set the 401 error handler to the lost password page in your `.htaccess`.
 * The hard part would be the first step. Depending on your current `.htaccess` 
   it could be pretty difficult to get working given that the default lost password
   page also runs through `wp-login.php`. Might require a custom plugin to create
   a separate lost password page.
 * Give it try and let me know!
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] [Plugin: HTTP Authentication] WordPress Failure notice on logout](https://wordpress.org/support/topic/plugin-http-authentication-wordpress-failure-notice-on-logout/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 2 months ago](https://wordpress.org/support/topic/plugin-http-authentication-wordpress-failure-notice-on-logout/#post-3042804)
 * By the way, this feature request is being discussed here:
 * [http://wordpress.org/support/topic/feature-request-network-setup](http://wordpress.org/support/topic/feature-request-network-setup)
 * Resolving this topic.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] Logging out](https://wordpress.org/support/topic/logging-out-3/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 2 months ago](https://wordpress.org/support/topic/logging-out-3/#post-3810243)
 * In standard HTTP authentication, once your browser has remembered the credentials
   there’s no way for the server to force it to forget those credentials. This makes
   full “logout” pretty much impossible, and unfortunately this plugin can’t design
   around it.
 * Here’s some background information:
 * [http://stackoverflow.com/a/449914](http://stackoverflow.com/a/449914)
 * Hope this helps!
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] HTTP Logout](https://wordpress.org/support/topic/http-logout/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 2 months ago](https://wordpress.org/support/topic/http-logout/#post-3674464)
 * If you there’s no way to force the browser not to send the credentials (e.g.,
   some authentication mechanisms support a separate logout mechanism) then the 
   simplest option is to send them to a URL that doesn’t ask for the credentials.
   Depending on your configuration this may need to be on a separate domain name.
 * Hope this helps!
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] HTTP Logout](https://wordpress.org/support/topic/http-logout/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/http-logout/#post-3674445)
 * It sounds like you’re trying to overload browser behavior that would typically
   initiate basic authentication.
 * WordPress may be stripping the raw at sign (the plugin shouldn’t do anything 
   to it). Was the at sign correctly displayed in the plugin settings page?
 * When you tried the URL-encoded version, did you try `%40`? Your post suggests
   you had an extra percent sign.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] Need to Interface with Custom Java Http Server](https://wordpress.org/support/topic/need-to-interface-with-custom-java-http-server/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/need-to-interface-with-custom-java-http-server/#post-3676850)
 * Any server which sets the `REMOTE_USER` variable in the environment (or something
   else) can be used. Normally this is provided via Apache’s authentication modules.
 * [http://httpd.apache.org/docs/current/mod/mod_authn_core.html](http://httpd.apache.org/docs/current/mod/mod_authn_core.html)
 * Because of the various authentication schemes available, I can’t provide much
   guidance on what a successful or unsuccessful authentication response would look
   like. Instead try reading up on HTTP basic authentication for an example:
 * [http://en.wikipedia.org/wiki/Basic_access_authentication](http://en.wikipedia.org/wiki/Basic_access_authentication)
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] [Feature Request] Network setup…](https://wordpress.org/support/topic/feature-request-network-setup/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/feature-request-network-setup/#post-3751537)
 * This is an oft-requested feature. I don’t have the time to add it myself but 
   I’d help someone who submits a patch!
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] Login Redirect Loop](https://wordpress.org/support/topic/login-redirect-loop-1/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/login-redirect-loop-1/#post-3593718)
 * Finally made some progress. In my case I found that the server was not following
   WordPress’s rewrite rules as expected.
 * The behavior I found which led to the redirect loop can be seen using cURL from
   the command line:
 *     ```
       $ curl -Ikv http://dev.example.com/wp-login.php
       * About to connect() to dev.example.com port 80 (#0)
       *   Trying 127.0.0.1... connected
       * Connected to dev.example.com (127.0.0.1) port 80 (#0)
       > HEAD /wp-login.php HTTP/1.1
       > User-Agent: curl/7.21.0 (x86_64-pc-linux-gnu) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3.4 libidn/1.15 libssh2/1.2.6
       > Host: dev.example.com
       > Accept: */*
       >
       < HTTP/1.1 302 Moved Temporarily
       HTTP/1.1 302 Moved Temporarily
       < Date: Tue, 28 May 2013 02:54:40 GMT
       Date: Tue, 28 May 2013 02:54:40 GMT
       < Server: Apache
       Server: Apache
       < WWW-Authenticate: Basic realm="Members Area"
       WWW-Authenticate: Basic realm="Members Area"
       < X-Pingback: http://dev.example.com/xmlrpc.php
       X-Pingback: http://dev.example.com/xmlrpc.php
       < Expires: Wed, 11 Jan 1984 05:00:00 GMT
       Expires: Wed, 11 Jan 1984 05:00:00 GMT
       < Cache-Control: no-cache, must-revalidate, max-age=0
       Cache-Control: no-cache, must-revalidate, max-age=0
       < Pragma: no-cache
       Pragma: no-cache
       < Location: http://dev.example.com/wp-login.php
       Location: http://dev.example.com/wp-login.php
       < Vary: Accept-Encoding
       Vary: Accept-Encoding
       < Content-Type: text/html; charset=UTF-8
       Content-Type: text/html; charset=UTF-8
       * no chunk, no close, no size. Assume close to signal end
   
       <
       * Closing connection #0
       ```
   
 * The 302 Moved Temporarily response (instead of 401 Unauthorized) suggested that
   the rewrite rules were not properly ending before the request was sent to WordPress.
   I confirmed this by disabling all rewrite rules and then selectively reenabling
   them until I got to the last one (where everything is sent to `/index.php`).
 * In my case I found from the Apache error log that the request was being internally
   rewritten to a different filename and thus bypassing the `%{REQUEST_FILENAME}`
   check:
 * `[Mon May 27 19:44:30 2013] [error] [client 127.0.0.1] File does not exist: /
   home/me/dev.example.com/failed_auth.html`
 * Adding the following to my `.htaccess` resolved the redirect loop:
 *     ```
       RewriteCond %{REQUEST_URI} ^/(stats/|missing\.html|failed_auth\.html) [NC]
       RewriteRule . - [L]
       ```
   
 * Your case may vary. I suggest inspecting the Apache error and rewrite logs for
   errors similar to the one above.
 * Your cURL should look like the following once you’ve pinned it down:
 *     ```
       $ curl -Ikv http://dev.example.com/wp-login.php
       * About to connect() to dev.example.com port 80 (#0)
       *   Trying 127.0.0.1... connected
       * Connected to dev.example.com (127.0.0.1) port 80 (#0)
       > HEAD /wp-login.php HTTP/1.1
       > User-Agent: curl/7.21.0 (x86_64-pc-linux-gnu) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3.4 libidn/1.15 libssh2/1.2.6
       > Host: plugindev.danieltwc.com
       > Accept: */*
       >
       < HTTP/1.1 401 Authorization Required
       HTTP/1.1 401 Authorization Required
       < Date: Tue, 28 May 2013 02:57:57 GMT
       Date: Tue, 28 May 2013 02:57:57 GMT
       < Server: Apache
       Server: Apache
       < WWW-Authenticate: Basic realm="Members Area"
       WWW-Authenticate: Basic realm="Members Area"
       < Vary: Accept-Encoding
       Vary: Accept-Encoding
       < Content-Type: text/html; charset=iso-8859-1
       Content-Type: text/html; charset=iso-8859-1
       * no chunk, no close, no size. Assume close to signal end
   
       <
       * Closing connection #0
       ```
   
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] Login Redirect Loop](https://wordpress.org/support/topic/login-redirect-loop-1/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 5 months ago](https://wordpress.org/support/topic/login-redirect-loop-1/#post-3593699)
 * I’ve managed to reproduce the problem with WordPress 3.5.1. Working on a fix!
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[HTTP Authentication] Login Redirect Loop](https://wordpress.org/support/topic/login-redirect-loop-1/)
 *  Plugin Author [Daniel Westermann-Clark](https://wordpress.org/support/users/dwc/)
 * (@dwc)
 * [13 years, 6 months ago](https://wordpress.org/support/topic/login-redirect-loop-1/#post-3593458)
 * Hi there,
 * Can you check whether you’ve also added a .htaccess to your wp-admin directory?
 * It sounds like you’ve protected wp-login.php with Shibboleth but not wp-admin.
   This would mean that the login checks in wp-admin fail since REMOTE_USER is not
   present.

Viewing 15 replies - 1 through 15 (of 36 total)

1 [2](https://wordpress.org/support/users/dwc/replies/page/2/?output_format=md) 
[3](https://wordpress.org/support/users/dwc/replies/page/3/?output_format=md) [→](https://wordpress.org/support/users/dwc/replies/page/2/?output_format=md)