Yeah, as far as I understand, you’re correct; this is definitely going to break challenge auth everywhere.
From conversation in the dev chat, it sounds like DW’s XML-RPC supports both challenge/response AND plain password auth. So for clients that still have their source code available, it should be very feasible to switch to password auth... but there’ll likely be some breakage in the meantime. No one’s thrilled about that, but also this wasn’t a change that could be avoided. 😬
no subject
From conversation in the dev chat, it sounds like DW’s XML-RPC supports both challenge/response AND plain password auth. So for clients that still have their source code available, it should be very feasible to switch to password auth... but there’ll likely be some breakage in the meantime. No one’s thrilled about that, but also this wasn’t a change that could be avoided. 😬