Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6227659
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 24, 20262026-05-24T09:15:40+00:00 2026-05-24T09:15:40+00:00

For a web page that exists, but for which a user does not have

  • 0

For a web page that exists, but for which a user does not have sufficient privileges (they are not logged in or do not belong to the proper user group), what is the proper HTTP response to serve?

401 Unauthorized?
403 Forbidden?
Something else?

What I’ve read on each so far isn’t very clear on the difference between the two. What use cases are appropriate for each response?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-24T09:15:41+00:00Added an answer on May 24, 2026 at 9:15 am

    A clear explanation from Daniel Irvine [original link]:

    There’s a problem with 401 Unauthorized, the HTTP status code for authentication errors. And that’s just it: it’s for authentication, not authorization.
    Receiving a 401 response is the server telling you, “you aren’t
    authenticated–either not authenticated at all or authenticated
    incorrectly–but please reauthenticate and try again.” To help you out,
    it will always include a WWW-Authenticate header that describes how
    to authenticate.

    This is a response generally returned by your web server, not your web
    application.

    It’s also something very temporary; the server is asking you to try
    again.

    So, for authorization I use the 403 Forbidden response. It’s
    permanent, it’s tied to my application logic, and it’s a more concrete
    response than a 401.

    Receiving a 403 response is the server telling you, “I’m sorry. I know
    who you are–I believe who you say you are–but you just don’t have
    permission to access this resource. Maybe if you ask the system
    administrator nicely, you’ll get permission. But please don’t bother
    me again until your predicament changes.”

    In summary, a 401 Unauthorized response should be used for missing
    or bad authentication, and a 403 Forbidden response should be used
    afterwards, when the user is authenticated but isn’t authorized to
    perform the requested operation on the given resource.

    Another nice pictorial format of how http status codes should be used.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have a web page that includes a bunch of images. Sometimes the image
I have a web page that displays a long line graph inside a div
I have a simple web page that till now didn't need any login. It
I have a web page that is being displaying in a winform app using
I have a web page that renders the same in IE7, Firefox, and Safari
I have a web page that consists of a checkbox (parent) and on this
I have a web page that displays a list of documents stored on the
I've got a web application that has a page full of batch files which
Redirect user to Login Page dependent on the Folder they are in. I have
How to implement a web page that scales when the browser window is resized?

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.