Re: Issue 146, was: Users with different access rights in HTTP Authentication

On 21.07.2010 14:43, Willy Tarreau wrote:
> ...
> Anyway, it still leaves open the expected behaviour on the client. What
> should a client do when facing such a response which indicates that
> (re-)authenticating as a different user *may* help satisfy the condition ?
> ...

The client can at least display a meaningful message ("you are not 
allowed to edit this resource" as opposed to "this resource is not 
editable").

For non-interactive clients (think remoting access to a CMS over HTTP), 
it may effect the type of error message sent up to the caller.

Best regards, Julian

Received on Wednesday, 21 July 2010 13:01:36 UTC