5 ms·
It is not 404. You need to log in.
by sachkris 10y ago
It is not 404. You need to log in.
- Washuu 10y agoThat is a terrible design by them. It should be 403 Forbidden.
- shangxiao 10y agoIt's a pattern to prevent information leakage
- Washuu 10y agoI assume to prevent exposing the names of private repositories, correct? For the main(global) search page it would seem reasonable easy to just omit that from the search results.
- stephengillie 10y agoThis way it can't be brute-scraped either.
- danneu 10y agoThat makes sense for endpoints like /admin, but it's more confusing than it's worth for users when the endpoint is otherwise rather public. Well, just see this comment thread. As an example, in this case with the /issues page, redirecting to `/login?redirect-to=/issues` would be more user-friendly since it signals that the page exists but you must authenticate.
- sachkris 10y agoNo, 403 implies the resource is unavailable even after authorization. 401 Unauthorized maybe the right one here.
- Matt3o12_ 10y agoGiving a 401 indicates that there might be a resource, though, which can also be harmful. It is fairly common to return a 404 to unauthorized users (or users with not enough permission) so you don't give away meta information. Granted, for the public search, it should return an appropriate error code but they should not do that for private repositories. Thus it think it is fair to assume that they have a policy: if user/guest does not have sufficient permission, always return an error 404.
- dayta 10y agoGitHub returns a 404 when you're not logged in, so ryanlol's statement is correct. Just try it, before claiming it is not curl -I https://github.com/issues?utf8=%E2%9C%93&q=is%3Aopen+is%3Aissue+ https://github.com/issues?utf8=%E2%9C%93&q=is%3Aopen+is%3Ais...