Skip to content

Example of WWW-Authenticate response should be HTTP 401 #64

Open
@aaronpk

Description

@aaronpk

https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-13.html#section-5.1

The HTTP response code is 400 in the example in this section. However the error description is "No access token was provided in this request". According to the error codes section of RFC6750, if no access token is provided, the RS should not include an error code at all, and should respond with HTTP 401.

I recommend we update the example in the RS Metadata draft to be consistent with RFC6750, since RS Metadata refers to that draft for the error codes already:

The HTTP status code and error string in the example response above are defined by [RFC6750].

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions