Auth: return 401 instead of 403 when the request isn't authenticated (RFC 9110) #18218
andershermansen
started this conversation in
Feature Requests & Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Current behavior
executeAccessthrowsForbidden(403) both when an authenticated user is denied by an access function and when there is no authenticated user at allWhy it bites
A JWT can be rejected for many reasons. All of them are swallowed by JWTAuthentication's catch (ignore) and returned as { user: null }, indistinguishable from sending no jwt at all.
We hit it with a jwt predating the authVersion requirement in the 3.90.0 security release. The call was rejected and surfaced as 403 "not allowed to perform this action". Since 403 means "re-authenticating won't help", nothing tells the client to drop the stale jwt and relogin. It just thinks it does not have access.
Proposal
Per RFC 9110: 401 when the request is unauthenticated (no credential, or one that was rejected); 403 when the identity is known and accepted but authorization still fails.
Maybe also include proper WWW-Authenticate header to stay even more compliant to the RFC.
Worth doing for 4.0 while it's still canary?
All reactions