# Basic Authentication with aFleX

**URL:** <https://community.a10networks.com/t/basic-authentication-with-aflex/185>\
**Category:** aFleX\
**Created:** [January 15, 2013, 5:55pm UTC](https://community.a10networks.com/t/basic-authentication-with-aflex/185 "2013-01-15T17:55:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![mischa](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mischa](https://community.a10networks.com/u/mischa)\
**Post date:** [January 15, 2013, 5:55pm UTC](https://community.a10networks.com/t/basic-authentication-with-aflex/185/1 "2013-01-15T17:55:23Z")

</div>

Quick and dirty way of authenticating users for specific URLs on a VIP.

```auto
\#\#\# START \#\#\#
when RULE\_INIT \{

```

# Set the REALM  
&nbsp;&nbsp;set ::REALM “Password Required”  
&nbsp;&nbsp;# List of URLs you need to authenticate for  
&nbsp;&nbsp;array set ::LISTURL {  
&nbsp;&nbsp;&nbsp;“/exchange” “1”  
&nbsp;&nbsp;&nbsp;“/exchange/” “1”  
&nbsp;&nbsp;&nbsp;“/sharepoint” “1”  
&nbsp;&nbsp;&nbsp;“/sharepoint/” “1”  
&nbsp;&nbsp;}  
&nbsp;&nbsp;# List of users (with passwords) that are allowed to authenticate  
&nbsp;&nbsp;array set ::DOTPASSWD {  
&nbsp;&nbsp;&nbsp;“randomuser1” “thiswillbeacleartextpassword”  
&nbsp;&nbsp;&nbsp;“randomuser2” “thiswillbeacleartextpassword”

```auto
  \}
\}
when HTTP\_REQUEST \{
  set URI [HTTP::uri]
  if \{ [info exists ::LISTURL($URI)] \} \{  
    if \{ [HTTP::header exists "Authorization"] \} \{
      set encoded\_header [HTTP::header "Authorization"]
      regexp -nocase \{Basic (.\*)\} $encoded\_header tmpmatch encoded\_string
      set decoded\_string [b64decode $encoded\_string]
      regexp -nocase \{(.\*):(.\*)\} $decoded\_string tmpmatch auth\_user auth\_passwd
      if \{ [info exists ::DOTPASSWD($auth\_user)] \} \{
        set stored\_passwd $::DOTPASSWD($auth\_user)
        if \{ $auth\_passwd ne $stored\_passwd \} \{
          HTTP::respond 401 WWW-Authenticate "Basic realm=\\"$::REALM\\""
        \}
      \} else \{
        HTTP::respond 401 WWW-Authenticate "Basic realm=\\"$::REALM\\""
      \}
    \} else \{
      HTTP::respond 401 WWW-Authenticate "Basic realm=\\"$::REALM\\""
    \}
  \}
\}
\#\#\# END \#\#\#

```
