Re: http error on access denied
From: Ivan Zhakov <chemodax_at_gmail.com>
Date: 2005-09-02 13:00:36 CEST
On 9/2/05, Branko Èibej <brane@xbc.nu> wrote:> Ivan Zhakov wrote:> > >On 9/1/05, Branko Èibej <brane@xbc.nu> wrote:> >> >> >>Branko Èibej wrote:> >>> >>> >>> >>>Ben Collins-Sussman wrote:> >>>> >>>> >>>> >>>>On Sep 1, 2005, at 8:19 AM, Ivan Zhakov wrote:> >>>>> >>>>> >>>>> >>>>>Hi!> >>>>>May be miss something, but I don't understand why subversion> >>>>>(mod_svn_authz) replies http error 401 (authorization failed) on> >>>>>access denied, instead of 403 (forbidden)? My opinion that 401 means> >>>>>that user provided invalid login/password pair, while 403 that user> >>>>>provided valid login/password but have no access to this area. Correct> >>>>>my if I wrong.> >>>>>> >>>>>> >>>>> >>>>> >>>>If the user provided invalid login/password, then *authentication*> >>>>failed. If the access was denied to a specific path, then> >>>>*authorization* failed.> >>>>> >>>> authentication == establishment of identity> >>>> authorization == checking of permissions> >>>>> >>>>The problem is that apache 2.0 muddles these |
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.