Uploaded image for project: 'WildFly Elytron'
  1. WildFly Elytron
  2. ELY-2895

Revert ELY-2548 BasicAuthenticationMechanism should return FORBIDDEN instead of UNAUTHORIZED

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Blocker Blocker
    • 2.7.0.Alpha1
    • None
    • HTTP
    • None

      After consulting https://datatracker.ietf.org/doc/html/rfc7235#section-3.1:
      If the request included authentication credentials, then the 401
      response indicates that authorization has been refused for those
      credentials.
      In the case of the authentication mechanism the authorization decision is in relation to the use of the credentials and is different to an authorization decision for a resource.

       

              darran.lofthouse@redhat.com Darran Lofthouse
              darran.lofthouse@redhat.com Darran Lofthouse
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: