Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
François Kooman
committed
Oct 7, 2015
1 parent
d53a858
commit c682944
Showing
1 changed file
with
3 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
c682944
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey, after reading https://en.wikipedia.org/wiki/List_of_HTTP_status_codes#4xx_Client_Error I'm not actually sure if this is correct. 'insufficient scope' should definitely be 401. I'll create a PR to make this clearer.
c682944
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
OK, so seems that OAuth 2.0 contradicts HTTP 1.1 there! :) https://tools.ietf.org/html/rfc7235#section-3.1
c682944
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Correction, it contradicts RFC2616, but that has been deprecated now.
Latest HTTP RFC text on 401s: http://tools.ietf.org/html/rfc7235#section-3.1
Latest HTTP RFC text on 403s: http://tools.ietf.org/html/rfc7231#section-6.5.3
So the "Authorization will not help" text from http://tools.ietf.org/html/rfc2616#section-10.4.4 is no longer true for 403s.
c682944
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So that means everything is correct in RS now. :)