What should I pass for the WWW-Authenticate header on 401s if I'm only using OpenID?

后端 未结 2 616
梦毁少年i
梦毁少年i 2020-12-24 11:48

The HTTP spec states:

10.4.2 401 Unauthorized

The request requires user authentication. The response MUST include a WWW-A

2条回答
  •  有刺的猬
    2020-12-24 12:34

    There is an OAuth Discovery spec that would indicate what to put into the WWW-Authenticate header -- if the spec were not obsolete without a replacement spec yet.

提交回复
热议问题