The biggest drawback of HTTP authentication, from the user's point of view, is probably the fact that you are getting an ugly dialog box and not a nice form embedded in your website.
You also cannot provide a link to the "registration" form or any help, as well as the information "I forgot my password."
For some back office, it is possible that authentication over the Internet is performed in the order; but I have some doubts about its use in some public office.
Another inconvenient situation is that there is no automatic logout function with HTTP authentication: with sessions, the session ends after a while or the cookie is automatically deleted when the user closes his browser ... But not with HTTP Authentication; therefore, for now, HTTP authentication seems less secure.
Pascal martin
source share