Password Protection / Basic-Auth

I agree that empty redirects won’t work (except for the Role rule). Have you tried just leaving those empty redirect rules out. Those shouldn’t be necessary.