What HTTP error code should I use for unauthorised access to a protected image?

Posted by Bala Clark on Stack Overflow See other posts from Stack Overflow or by Bala Clark
Published on 2011-01-06T09:46:55Z Indexed on 2011/01/06 9:53 UTC
Read the original article Hit count: 377

Filed under:
|

I am writing a web application that has secure images uploaded by users. These images are only available to the owner when logged in. I am wondering what the best HTTP error code to throw in the case of unauthorised access? Would a 404 not found, or a 403 unauthorised be better?

I am leaning towards the 403, but would it be better to hide the fact that the resource exists to unauthorised users be better?

© Stack Overflow or respective owner

Related posts about http

Related posts about error-handling