jsr339-experts@jax-rs-spec.java.net

[jsr339-experts] Re: Client Authorization

From: Sergey Beryozkin <sberyozkin_at_talend.com>
Date: Tue, 30 Oct 2012 10:08:59 +0000

+1
On 28/10/12 23:23, Bill Burke wrote:
> IMO, we should add a ForbiddenException. I have already logged a JIRA on
> this awhile back. We throw it on role-check failures.
>
> On 10/27/2012 10:02 AM, Markus KARG wrote:
>> Experts,
>>
>> possibly another dumb question, please don't mind. :-)
>>
>> Does the JAX-RS 2.0 specification mandate that a compliant
>> implementation of the Client API MUST throw some kind of
>> SecurityException in case a 403 Forbidden is received?
>>
>> Thanks
>>
>> Markus
>>
>