# \[Mobilizon\] re-enable protect\_against\_basic\_auth\_spoofing in package?

**URL:** https://forum.yunohost.org/t/mobilizon-re-enable-protect-against-basic-auth-spoofing-in-package/43059
**Category:** Support apps
**Tags:** mobilizon, english
**Created:** [September 23, 2026, 5:17pm UTC](https://forum.yunohost.org/t/mobilizon-re-enable-protect-against-basic-auth-spoofing-in-package/43059 "2026-09-23T17:17:59Z")
**Posts on this page:** 1
**Showing post:** 11

<div class="post-metadata">

### Author: ![tmb](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/t/7c8e57/32.png) [@tmb](https://forum.yunohost.org/u/tmb)
#### Post date: [September 26, 2026, 9:47am UTC](https://forum.yunohost.org/t/mobilizon-re-enable-protect-against-basic-auth-spoofing-in-package/43059/11 "2026-09-26T09:47:54Z")

</div>

not sure if this would work in the manifest.toml:  
(if mobilizon really has a need? webdav?)

```toml
    [install.protect_against_basic_auth_spoofing]
    ask.en = "Block all basic auth comming from clients (not SSO generated) ?"
    help.en = "May have to be disabled for WebDav/CalDav clients, not for "randomized" ICS/webcal download links."
    type = "bool"
    default = nil

```

And for making the SSO work: [SSO: still default pw injection & apps that use email as login broken?](https://forum.yunohost.org/t/sso-still-default-pw-injection-apps-that-use-email-as-login-broken/43075)

---

_[View the full topic](https://forum.yunohost.org/t/mobilizon-re-enable-protect-against-basic-auth-spoofing-in-package/43059)._
