\[~ann.campbell.2] I was a little confused at first by the starting of the first sentence and thought you got the title of the rule wrong. I would rewrite this sentence like : "Basic authentication uses Base64 as... "
I remove CWE-311 from this rule because CWE-311 maps to "INSECURE_CONF" SonarSource Security Category and this makes this RSPEC mapping to 2 SonarSource Security Category and we expect a given RSPEC to map to only one specific SonarSource Security Category.