By tolerating unknown extra rpcauth parameters (and ignoring the rpcauth), we can ensure a limited forward compatibility by not forcing users to downgrade their config file to switch back to older versions (perhaps temporarily).
To avoid any possible confusion, a message is still printed at startup, and returned as part of the error message if the user attempts to authenticate using the correct username/password.