ok, i found
it is Exploder that ignores user/pass in the URL, until the page is denied.
but i can't deny the root page if it is not actually protected, because this would cause unauthenticated users to not browse unprotected resources.
...looking for a solution... :read: