Skip to content

Basic Auth

Basic Auth middleware provides HTTP basic authentication.

  • For valid credentials it calls the next handler.
  • For missing or invalid credentials, it sends a 401 Unauthorized response.

All core middleware lives in the middleware package:

import "github.com/labstack/echo/v5/middleware"
e.Use(middleware.BasicAuth(func(c *echo.Context, username, password string) (bool, error) {
// Use a constant time comparison to prevent timing attacks.
if subtle.ConstantTimeCompare([]byte(username), []byte("joe")) == 1 &&
subtle.ConstantTimeCompare([]byte(password), []byte("secret")) == 1 {
return true, nil
}
return false, nil
}))
e.Use(middleware.BasicAuthWithConfig(middleware.BasicAuthConfig{}))

BasicAuthConfig · github.com/labstack/echo/[email protected]

Fields from package source
FieldTypeDescriptionSource
SkipperSkipperSkipper defines a function to skip middleware.L23
ValidatorBasicAuthValidatorValidator is a function to validate BasicAuthWithConfig credentials. Note: if request contains multiple basic auth headers this function would be called once for each header until first valid result is returned Required.L28
RealmstringRealm is a string to define realm attribute of BasicAuthWithConfig. Default value "Restricted".L32
AllowedCheckLimituintAllowedCheckLimit set how many headers are allowed to be checked. This is useful environments like corporate test environments with application proxies restricting access to environment with their own auth scheme. Defaults to 1.L38
Functions from package source
TypeSource
func BasicAuth(fn BasicAuthValidator) echo.MiddlewareFuncL87
func BasicAuthWithConfig(config BasicAuthConfig) echo.MiddlewareFuncL92

The Validator has the signature:

type BasicAuthValidator func(c *echo.Context, user string, password string) (bool, error)
// Effective defaults applied when fields are left unset.
BasicAuthConfig{
Skipper: DefaultSkipper,
Realm: "Restricted",
}