Hi,
i'm happy. It works very well. Thank you!
On a quick test i found only one little drawback:
You can't log off!

But, this is not a real show stopper, i would say it works like designed.
And, to prevent false bug reports, you should mention that this only works if the auth method used by the web server does send a cleartext password. I have configured a auth using radius and that sends the password as cleartext (using https, of course).
But, if i'm not wrong, kerberos or ntlm for example will not work.
To make that auths (and every auth else) working: If there is a remote_user available, the authentication always was successful. Can the http_auth plugin modified (maybe using a non config switch that is disabled by default) to make zp happy if only the user is set, without doing any password checks?