Anyone could host a copy of a front end on a server of their own, collect a person's password there, and replay it as HTTP Basic against JMAP or the API. Cross-origin rules don't stop that, since a server isn't a browser, and neither does client registration, since Basic never goes through OAuth (contract C-23). JMAP (session, API, upload, download, event source, WebSocket), /api, /auth/introspect, /auth/userinfo and authenticated /auth/register now refuse an Authorization: Basic header before looking at the password, with a 401 whose only challenge is Bearer. A wrong password gets the same answer as the right one. CalDAV and CardDAV keep Basic, and their 401s still offer it. The sign-in page's /api/auth takes the password in its body and is unaffected, as is the token endpoint's client authentication. Bootstrap and recovery mode accept Basic everywhere, as they keep permissive CORS. INBUXA_HTTP_BASIC_AUTH=all puts it back everywhere; dav is the default, and any other value logs a warning and keeps it. Test builds accept Basic everywhere, since the integration suites sign in with passwords, and legacy_protocols.py sets the variable. Tested: unit tests for the paths, and tests/e2e/http_basic_auth.py against the debug build, 26 checks, including both front ends' sign-in path and a refused unregistered redirect for an ordinary account.