Bug#92052: Present in apache 2 & workaround

clone 92052 -1
reassign -1 apache2
found -1 2.2.3-4

Ideally a granular (at least per-vhost) option to enable or disable this
feature would be useful--I would like to allow certain (fast)cgi scripts
the ability to process HTTP authentication, but I don't want others
having access to the usernames/passwords that my users authenticate

The following mod_rewrite rules implement a workaround:

        RewriteCond %{HTTP:Authorization} (.*)
        RewriteRule . - [env=HTTP_AUTHORIZATION:%1]

These directives are granular down to the directory/.htaccess level. :)

