2015May core #1241 - Require 403 Response for Unauthorized Access.

XMLWordPrintableJSON

    • Type: Change Request
    • Resolution: Persuasive with Modification
    • Priority: Medium
    • FHIR Core (FHIR)
    • DSTU1 [deprecated]
    • Security
    • REST (http)
    • 2.1.0.3
    • Hide

      Motion: Add to the existing language something like "unless you have a specific reason, you should always return a 404".

      Show
      Motion: Add to the existing language something like "unless you have a specific reason, you should always return a 404".
    • Jonathan Coleman / Grahame Grieve: 14-0-0
    • Enhancement
    • Non-substantive
    • DSTU1 [deprecated]

      Existing Wording: The choice of whether to return 403 or 404 depends upon the specific situation and specific local policies, regulations, and laws.

      Proposed Wording: Servers SHALL respond with 403 responses when a client is not authorized.

      Comment:

      403 Responses ensure that a PI disclosure to an unauthorized client do not occur, and are standard practice for common authorization solutions. See Comment #2 for rationale on SHALL versus SHOULD.

            Assignee:
            Unassigned
            Reporter:
            seanmoore
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: