HTTP status code for missing authentication

前端 未结 3 525
野趣味
野趣味 2020-12-31 01:08

HTTP defines the status 401 Unauthorized for missing authentication, but this status only applies to HTTP authentication. What status should I return with a session cookie b

3条回答
  •  没有蜡笔的小新
    2020-12-31 01:31

    Formally, 403 Forbidden is the right response. It's defined as

    Authorization will not help and the request SHOULD NOT be repeated.

    The confusing part may be "Authorization will not help", but they really mean "HTTP authentication" (WWW-Authenticate)

提交回复
热议问题