I would like to have my Plack app try several different means of authorizing the user. Specifically, check if the user is already authorized via a session cookie, then check for Digest authentication and then fall back to Basic.
I figured I could just enable a bunch of Auth handlers in the order I wanted them to be checked (Session, Digest, Basic). Unfortunately, the way that Plack::Middleware::Auth::Digest and Plack::Middleware::Auth::Basic are written they both return 401 if digest or basic auth doesn’t exist, respectively.
How is this normally dealt with in Plack?
I do not have an implementation but I think I have the approach. You can do this “in-line” with Plack::Middleware::Conditional. So it would look like this but you’ll have to fill in the missing conditions/tests. I didn’t see an easy/obvious way but I suspect you might. Since you have the
$envto pass around you should be able to set/check HTTP_/session stuff in the order you want and keep the state for the next handler to know if it should be enabled or not.