···1+diff --git i/main.go w/main.go
2+index bf80f3d..632f7d6 100644
3+--- i/main.go
4++++ w/main.go
5+@@ -174,7 +174,7 @@ func handleAuthRequest(res http.ResponseWriter, r *http.Request) {
6+ case plugins.ErrNoValidUserFound:
7+ // No valid user found, check whether special anonymous "user" has access
8+ // Username is set to 0x0 character to prevent accidental whitelist-match
9+- if mainCfg.ACL.HasAccess(string(0x0), nil, r) {
10++ if mainCfg.ACL.HasAccess(string(rune(0x0)), nil, r) {
11+ mainCfg.AuditLog.Log(auditEventValidate, r, map[string]string{"result": "anonymous access granted"}) // #nosec G104 - This is only logging
12+ res.WriteHeader(http.StatusOK)
13+ return