3 ms·
Why not? 401 seems like a fine fit if your client doesn't need to differentiate between authentication and authorization; most don't need to at all. Also, you
by throwaway91111 9y ago
Why not? 401 seems like a fine fit if your client doesn't need to differentiate between authentication and authorization; most don't need to at all.
Also, you can fail authorization without passing authentication. For instance, you could be authorized by ip range or something unrelated to any of the data in the http request.
- BillinghamJ 9y ago> Why not? Because those are the semantics as-per the spec. In relation to your latter point, 403 also covers any other reasons your access is forbidden - e.g. IP ranges etc.
- erikpukinskis 9y agoWut. Most clients don't need to differentiate between "you're not allowed to do that" and "you're not logged in"? Those things require totally different reactions, no?