I ran into something pretty strange while setting up rest-server on a Raspberry Pi 4 and wanted to report it since I couldn't find anything matching it in existing issues.
Running rest-server 0.14.0 (compiled with go1.24.3 on linux/arm64) on Raspberry Pi OS. No matter what I did, every single request got rejected with 401 Unauthorized, even though I could prove the password was correct.
I went through this pretty thoroughly because I assumed I was just making a typo somewhere (which, to be fair, did happen once along the way!). But even after ruling that out completely, it kept failing. I tried regenerating the htpasswd file with bcrypt (-B), SHA-256 (-2), and apr1-MD5 (-m) — all three gave a 401 and the debug log showed Invalid htpasswd entry for my user. So I figured maybe those formats weren't actually supported despite the docs mentioning them.
Then I noticed a comment in your own htpasswd.go saying entries need to be created with -s (SHA-1), so I tried that instead. This time the debug log didn't complain about the entry at all — no more "invalid entry" message — but it still returned 401 on every request.
At that point I wanted to be really sure it wasn't me, so I checked it two independent ways:
htpasswd -v on the file said the password was correct
I manually hashed the password myself with openssl dgst -sha1 -binary | base64 and compared it directly against what was stored in the file — it matched exactly, byte for byte
So the password was provably right, the file parsed cleanly, and it was still getting rejected. I also ruled out the network/tunnel as a factor by testing locally on the same machine rest-server was running on — same result.
In the end I gave up and switched to --no-auth.
I ran into something pretty strange while setting up rest-server on a Raspberry Pi 4 and wanted to report it since I couldn't find anything matching it in existing issues.
Running rest-server 0.14.0 (compiled with go1.24.3 on linux/arm64) on Raspberry Pi OS. No matter what I did, every single request got rejected with 401 Unauthorized, even though I could prove the password was correct.
I went through this pretty thoroughly because I assumed I was just making a typo somewhere (which, to be fair, did happen once along the way!). But even after ruling that out completely, it kept failing. I tried regenerating the htpasswd file with bcrypt (-B), SHA-256 (-2), and apr1-MD5 (-m) — all three gave a 401 and the debug log showed Invalid htpasswd entry for my user. So I figured maybe those formats weren't actually supported despite the docs mentioning them.
Then I noticed a comment in your own htpasswd.go saying entries need to be created with -s (SHA-1), so I tried that instead. This time the debug log didn't complain about the entry at all — no more "invalid entry" message — but it still returned 401 on every request.
At that point I wanted to be really sure it wasn't me, so I checked it two independent ways:
htpasswd -v on the file said the password was correct
I manually hashed the password myself with openssl dgst -sha1 -binary | base64 and compared it directly against what was stored in the file — it matched exactly, byte for byte
So the password was provably right, the file parsed cleanly, and it was still getting rejected. I also ruled out the network/tunnel as a factor by testing locally on the same machine rest-server was running on — same result.
In the end I gave up and switched to --no-auth.