Compute the username* value for a challenge offering userhash=true
(RFC 7616 §3.4.4): base64(H(username : realm)).
A server that sends userhash=true is telling the client not to send the
username in the clear. The previous code parsed the flag, exposed it on the
public DigestChallenge type with a JSDoc promising support, and then
ignored it — sending a plain username="admin" back to a server that had
explicitly asked for it to be hashed. That is a privacy regression, and the
server rejects the request too, because HA1 was built from the unhashed name.
Compute the
username*value for a challenge offeringuserhash=true(RFC 7616 §3.4.4):base64(H(username : realm)).A server that sends
userhash=trueis telling the client not to send the username in the clear. The previous code parsed the flag, exposed it on the public DigestChallenge type with a JSDoc promising support, and then ignored it — sending a plainusername="admin"back to a server that had explicitly asked for it to be hashed. That is a privacy regression, and the server rejects the request too, because HA1 was built from the unhashed name.