app.use(bruteforce.prevent, function(req, res, next) { var user = basicAuth(req); if (user && user.name === auth.username && user.pass === auth.password) { // Successful authentication, reset rate limiting. req.brute.reset(next); } else { res.statusCode = 401; res.setHeader('WWW-Authenticate', 'Basic realm="terriajs-server"'); res.end('Unauthorized'); } });