I have several pages designed to be called with AJAX – I have them return an abnormal status code if they can’t be displayed, and my javascript will show an error box accordingly.
For example, if the user is not authenticated or their session has timed out and they try to call one of the AJAX pages, it will return 401 Unathorized.
I also have some return 500 Internal Server Error if something really odd happens server-side.
What status code should I return if one of these pages was called without required parameters? (and therefore can’t return any content).
I had a look at the wikipedia article on HTTP status codes, but the closest one I could find to the code I’m looking for was this:
422 Unprocessable Entity
The request was well-formed but was unable to be followed due to semantic errors.
Edit: The above code is WebDAV specific and therefore unlikely to be appropriate in this case
Can anyone think of an appropriate code to return?
You could pick
404 Not Found:(highlight by me)
404 Not Foundis a subset of400 Bad Requestwhich could be taken as well because it’s very clear about what this is:This is normally more common with missing/wrong-named post fields, less with get requests.
As Luca Fagioli comments, strictly speaking 404, etc. are not a subset of the 400 code, and correctly speaking is that they fall into the 4xx class that denotes the server things this is a client error.
In that 4xx class, a server should signal whether the error situation is permanent or temporary, which includes to not signal any of it when this makes sense, e.g. it can’t be said or would not be of benefit to share. 404 is useful in that case, 400 is useful to signal the client to not repeat the request unchanged. In the 400 case, it is important then for any request method but a HEAD request, to communicate back all the information so that a consumer can verify the request message was received complete by the server and the specifics of "bad" in the request are visible from the response message body (to reduce guesswork).
I can’t actually suggest that you pick a WEBDAV response code that does not exist for HTTP clients using hypertext, but you could, it’s totally valid, you’re the server coder, you can actually take any HTTP response status code you see fit for your HTTP client of which you are the designer as well:
IIRC request entity is the request body. So if you’re operating with request bodies, it might be appropriate as Julian wrote.
You commented:
That could be, but it can be anything syntactically expressed, the whole request, only some request headers, or a specific request header, the request URI etc.. 400 Is not specifically about "HTTP string syntax", it’s infact the general answer to a client error:
The important part is here that you must tell the client what went wrong. The status code is just telling that something went wrong (in the 4xx class), but HTTP has not been specifically designed to make a missing query-info part parameter noteable as error condition. By fact, URI only knows that there is a query-info part and not what it means.
If you think 400 is too broad I suggest you pick 404 if the problem is URI related, e.g.
$_GETvariables.