RFC2616: Do I really need to set WWW_Authenticate when returning 401?

According to RFC2616 , if I return 401 in response to a request to my (Ruby) server, I "MUST enable the WWW-Authenticate header field." It's true? Not setting a title seems to have no negative impact. I use Merb as a web framework and it does not force me to set the title.

Am I missing something or is this rule more respected in violation?

Should web frameworks force the developer to set the title when returning 401?

+3
source share
2 answers

, , 401 . WWW-Authenticate, 401 " " " ". , , , - "".

+4

401, , , , .

, , ? " ", 403.

+1

Source: https://habr.com/ru/post/1740226/


All Articles