4 ms·
The author seems confused between 401 (not logged in) and 403 (user doesn't have permission).
by gjjrfcbugxbhf 9y ago
The author seems confused between 401 (not logged in) and 403 (user doesn't have permission).
- adrianmsmith 9y agoAgreed: 401 is for authentication and 403 for authorization. Yet the official name for 401 is 401 UNAUTHORIZED. So even the very basics of REST and HTTP are confusingly or ambiguously defined.
- combatentropy 9y agoThe old spec, https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html, seems to say that 401 can mean either unauthenticated or unauthorized. If you haven't signed in, it means unauthenticated. If you have signed in, then it means unauthorized. Were the status codes written before authenticate and authorize had the narrow meanings of today? Meanwhile, 403 seems to be reserved for when the server just generally doesn't want to do what you're asking it to do. It may tell you, it may not, it doesn't have to tell you, so there. "Authorization will not help..."