JavaScriptSeverity: InfoStatus: Fixed

README examples: handle a missing Authorization header

Docs-only PR: in v3, parse() expects a string, so the README examples now pass req.headers.authorization ?? '' to match the upgrade instructions. A request without an Authorization header then gets undefined back (and a 401 in the http server example). Merged.

Timeline

Fixed upstream 1 day after it was found.

  1. Found
  2. Reported via pull request
  3. Disclosed publicly
  4. Fix merged
  5. Entry last updated

Machine-readable: JSON · Markdown · ID docs/javascript/jshttp__basic-auth/2026-10-07-readme-missing-authorization-header