Why not all authorization requirements included in ForbiddenResponseOperationFilter? #14
Replies: 5 comments
-
Forbidden means you have access to the site but you are not allowed to access the resource within the site. Are there other you think should be included? |
Beta Was this translation helpful? Give feedback.
-
Why not just check for any |
Beta Was this translation helpful? Give feedback.
-
You don't want to include Also we can't be sure if any custom requirements a developer creates should create a 401 or 403, so I'm very explicit here about types that should create a 403. |
Beta Was this translation helpful? Give feedback.
-
I thought that requirement must produce 403 only |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
-
Why only these requirements are included?
Beta Was this translation helpful? Give feedback.
All reactions