Hey Jon:

Redirects are used for sending the user to an https URL. Im guessing if you dont need that, it should be possible to authenticate without a redirect. cookies are not needed if you dont care about authentication overhead. our "per-dataset" authentication got rather complicated because we were trying to use https for authentication but send the data over http to avoid the enccyption overhead. We'll have to look at how to make the simple case simple.

I assume this is in the context of TDS/ncWMS ?

In the meanwhile, you might want to look at this page, assuming you can get in:

On 4/7/2010 3:43 AM, Jonathan Blower wrote:

I'd like to be able to restrict access to a THREDDS server on a
per-dataset basis.  I note from the documentation
ccess.html) that the current scheme involves HTTP redirects and session
cookies.  However, some of the clients we use are not able to handle
redirects or cookies.

I would like to have per-dataset security which simply uses HTTP Basic
or Digest authentication without redirects or sessions.  I don't have an
immediate need for using SSL to encrypt passwords.  How can I go about
doing this?  I'd be comfortable creating new code that can be plugged in
to THREDDS if necessary.


