What HTTP code to use in “Not Authenticated” and “Not authorized” cases?

后端 未结 4 980
死守一世寂寞
死守一世寂寞 2021-02-03 23:34

I read that \"401 Unauthorized\" code must be used when a user:

  1. Is not logged, but login is required (\"not authenticated\");
  2. Is logged, but his profile d
4条回答
  •  误落风尘
    2021-02-04 00:02

    I believe 403 is the right one. We may have to tune the language in the specification to make that clear.

提交回复
热议问题