3 ms·
This looks pretty interesting. A small thing: For cancelled DELETE requests like shown in the video, it would be better to return 403 Forbidden [1] instead of
by jkbr 14y ago
This looks pretty interesting.
A small thing: For cancelled DELETE requests like shown in the video, it would be better to return 403 Forbidden [1] instead of 400 Bad Request [2]:
10.4.1 400 Bad Request
The request could not be understood by the server due to malformed syntax.
Vs.
10.4.4 403 Forbidden
The server understood the request, but is refusing to fulfill it.
[1] http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10.4.4 http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10...
[2] http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10.4.1 http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10...
- dallonf 14y agoThat's actually possible, 400 is just the default code: cancel("You're not allowed to do that", 403); I'm not sure why we didn't show that in the video. Edit: Unless you're saying that 403 should be the default code?
- jeromegn 14y agoSounds like 400 is the right code for cancelling a request in general. The way you have it setup is fine in my opinion. Maybe add some sugar like: `needsAuth()` which would check for a user and would return `cancel("You're not allowed to do that", 403)` given the user does not exist. I don't think that's necessary though. I like how it is right now. Great work.