401 Unauthorized loop caused by cached expired basic-auth credentials in Dart HttpClient
0 reputation · 28 Mar 2023, 10:44 UTC
Determine whether Dart's HttpClient should automatically discard cached basic-auth credentials after a server returns HTTP 401 Unauthorized due to expired or invalid credentials, thereby breaking the repeat-authentication loop.
The SDK notes that credential handling is the caller's responsibility and that the client does not clear cached credentials on a 401 response, which can cause unnecessary traffic and potential denial-of-service in long-running services.
Given that future Dart SDK versions might change this caching policy, what is the expected behavior for credential expiration, and should the API provide an automatic invalidation mechanism or remain explicit?