From: Fabian Keil 
Table 1. Default Configurations
@@ -314,7 +314,7 @@ actions.Note that some actions, like @@ -339,7 +339,7 @@
The easiest way to edit the actions files is with a browser by using @@ -529,7 +529,7 @@
The matching of the domain part offers some flexible options: if @@ -634,7 +634,7 @@
Privoxy uses 
 
        Note that many of these actions have the potential to cause a page
@@ -4495,7 +4495,7 @@ example.org/instance-that-is-delivered-as-xml-but-is-not
       together: Remember all actions
@@ -4544,7 +4544,7 @@ example.org/instance-that-is-delivered-as-xml-but-is-not
        If you aren't a developer, there's no need for you to edit the
@@ -4887,7 +4887,7 @@ wiki.
        So far we are painting with a broad brush by setting general
diff --git a/doc/webserver/user-manual/appendix.html b/doc/webserver/user-manual/appendix.html
index 5a07a155..9b1cc1bf 100644
--- a/doc/webserver/user-manual/appendix.html
+++ b/doc/webserver/user-manual/appendix.html
@@ -293,7 +293,7 @@
      Since Privoxy proxies each
@@ -313,7 +313,7 @@
 
        Privoxy main page: Privoxy main page: 
            Show information about the current configuration, including
-          viewing and editing of actions files: 
 
          Show the source code version numbers: Show the source code version numbers: 
 
          Show the browser's request headers: Show the browser's request headers: 
 
          Show which actions apply to a URL and why: Show which actions apply to a URL and why: "off", "Privoxy" continues to run, but only as a
           pass-through proxy, with no actions taking place: Short cuts. Turn off, then on: Short cuts. Turn off, then on: Whether or not proxy authentication through Privoxy should work. 0 or 1 0 Proxy authentication headers are removed. Privoxy itself does not support proxy authentication, but
+              can allow clients to authenticate against Privoxy's parent
+              proxy. By default Privoxy (3.0.21 and later) don't do that and
+              remove Proxy-Authorization headers in requests and
+              Proxy-Authenticate headers in responses to make it harder for
+              malicious sites to trick inexperienced users into providing
+              login information. If this option is enabled the headers are forwarded. Enabling this option is not recommended if there is no parent
+              proxy that requires authentication or if the local network
+              between Privoxy and the parent proxy isn't trustworthy. If
+              proxy authentication is only required for some requests, it is
+              recommended to use a client header filter to remove the
+              authentication headers for requests where they aren't
+              needed.8.5.35.
+        
8.5.35.
         Summary
 
         8.7.1.
+        
8.7.1.
         match-all.action
 
         8.7.2.
+        
8.7.2.
         default.action
 
         8.7.3.
+        
8.7.3.
         user.action
 
         14.2. Privoxy's
+      
14.2. Privoxy's
       Internal Pages
 
       
         
             
             
             
             
 
           
             
             
           
 
-          
             
-          
+          
             
7.4.9.
+        enable-proxy-authentication-forwarding
+
+        
+            
+
Privoxy's user interface can be @@ -63,8 +63,10 @@ -
+