There was originally no requirement for TLS when using Basic
Authentication.
There is a requirement for TLS when using the out of
spec Bearer Token scheme, but this requrement is defined
in the RFC and does not need to be called out explicitly.
Thanks for submitting this pull request! I'm here to inform the recipients of the pull request that you and the commit authors have already signed the CLA.
There was originally no requirement for TLS when using Basic Authentication.
There is a requirement for TLS when using the out of spec Bearer Token scheme, but this requrement is defined in the RFC and does not need to be called out explicitly.
[fixes #571]