And it’s superior in many ways, since the file is never delivered until authentication has been completed.
This means you must have a secondary channel to communicate to the user about the password, and the server must also know the password.
So depending on your use-case, the basic auth isn't suitable. For example, mega : https://en.wikipedia.org/wiki/Mega_(service) , in which you want to ensure that the decrypted data is _not_ accessible to the server, so the key is not stored nor sent to the server!
//<user>:<pass>@<url>[:<port>][/<location>]/
It doesn’t work on IE classic, but should still be perfectly valid on Chrome, Safari, Firefox, etc.
That means nothing to maintain, no server cost, no serverless functions to rely on, etc.
But when that's not a constraint there are many different options that might make more sense.
It’s just weird how many people are jumping on this as some new technique when Basic Auth is fully usable in many other cases.