I don't know, the docs on apache say:
Make sure that the AuthUserFile is stored outside the document tree of the web-server; do not put it in the directory that it protects. Otherwise, clients may be able to download the AuthUserFile.
That would lead one to believe it should have worked...