3 ms·
If we're going to pedant about status codes, it seems like 401 is correct. 500 is a "server error" range, 503 would imply the service is down due to server side
by d_watt 4y ago
If we're going to pedant about status codes, it seems like 401 is correct. 500 is a "server error" range, 503 would imply the service is down due to server side issues.
401:"not authorized" seems exactly correct for status page saying "I know who you are, and what you want, but you can't have it because you chose to disable your account."
- chrismorgan 4y agoI am assuming account-specific endpoints, which on reflection isn’t guaranteed, but is I think reasonable to expect. On a shared endpoint, 401 would be reasonable, but on a dedicated endpoint I maintain it’s unreasonable and incorrect. 401 is only permitted if an Authorization header is missing or insufficient, and the server “MUST send a WWW-Authenticate header field containing at least one challenge applicable to the target resource” (https://www.rfc-editor.org/rfc/rfc9110#name-401-unauthorized https://www.rfc-editor.org/rfc/rfc9110#name-401-unauthorized). Presuming an account-specific status page endpoint, this cannot be satisfied; nothing the client can send will work, therefore it’s far more reasonably treated as a server error than a client error: the server has been instructed not to service these requests. “Service Unavailable” is clearly suitable. (Refusing the connection would also be reasonable, and have certain technical advantages for machine use.)