401 Unauthorized vs 403 Forbidden: Which is the right status code for when the user has not logged in? [duplicate]
The exact satisfying one-time-for-all answer I found is: Short answer: 401 Unauthorized Description: While we know first is authentication (has the user logged-in or not?) and then we will go into authorization (does he have the needed privilege or not?), but here’s the key that makes us mistake: But isn’t “401 Unauthorized” about authorization, not … Read more