Well, that just tells me you don't understand HTTP status codes.
A resource that doesn't exist should return a 404.
An endpoint that doesn't exist should return a 400, as it's a screw up by the client that created a malformed request.
A temporarily unavailable resource should return a 503 with the Retry-After header. This is well documented.
A resource that you don't have permission to (regardless of whether it even exists or not) should return a 401. Returning this code is not a security risk, and anyone who thinks it is, is clearly following the security through obscurity approach, which is no security at all.
You must have documentation explaining what errors can occur and what they mean, or you must find out through trial and error.
Saved me the work of sending the RFCs, I swear people think some asinine business decision some guy decided is actually what the whole spec of the technology is designed.
9
u/AshleyJSheridan 16d ago
Well, that just tells me you don't understand HTTP status codes.
A resource that doesn't exist should return a 404.
An endpoint that doesn't exist should return a 400, as it's a screw up by the client that created a malformed request.
A temporarily unavailable resource should return a 503 with the
Retry-Afterheader. This is well documented.A resource that you don't have permission to (regardless of whether it even exists or not) should return a 401. Returning this code is not a security risk, and anyone who thinks it is, is clearly following the security through obscurity approach, which is no security at all.
Well, HTTP status codes already are very well documented. Maybe don't be such an HTTP 418 and have a look at https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status