Skip to main content

Alex Polo

Member since Aug 10, 2012

Recent Blog Comments By Alex Polo

  • Handling Forbidden RESTful Requests: 401 vs. 403 vs. 404

    Posted on Aug 19, 2012 at 10:10 PM

    @Ben, Probably I was not very clear but "Your username and/or password is incorrect" is what I meant. What does it tell to one about the underlying data? No more than that the credentials one has provided are incorrect. Isn't it the case when Sarah is trying to access Tricia's profile? Sa... read more »

  • Handling Forbidden RESTful Requests: 401 vs. 403 vs. 404

    Posted on Aug 18, 2012 at 9:50 PM

    @Ben, Sure, so why you choose 404 over 401? Is there any particular reason? I just think that 401 makes more sense and is more appropriate in this situation, isn't it? As an example, when you log in to a web site and accidentally has entered wrong credentials, most of the sites will notify you that... read more »

  • Handling Forbidden RESTful Requests: 401 vs. 403 vs. 404

    Posted on Aug 10, 2012 at 3:49 AM

    Hi Ben! Why not return 401 in both cases: whether the user exists or not? That way no clue would be leaked to the hacker, too. 401 simply says you don't have the right to do what you want (i.e. because you're not the person who this resource may belong to). Whereas, 404 says we just don't have what ... read more »

I believe in love. I believe in compassion. I believe in human rights. I believe that we can afford to give more of these gifts to the world around us because it costs us nothing to be decent and kind and understanding. And, I want you to know that when you land on this site, you are accepted for who you are, no matter how you identify, what truths you live, or whatever kind of goofy shit makes you feel alive! Rock on with your bad self!
Ben Nadel