• Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    12
    ·
    edit-2
    6 hours ago

    I don’t respect them because most instances a 403 is more than adequate for your security. The only time I agree with having a 404 over a 403 would be file-specific pathing, but realistically the entire file directory should be a 403 instead of a 404, And then if the user is authorized to access the resource(but it isn’t there), then it gives a 404.