Skip to content

Commit

Permalink
make release note more accurate, only one endpoint affected #10340
Browse files Browse the repository at this point in the history
  • Loading branch information
pdurbin committed Dec 20, 2024
1 parent f99d67e commit a2cb8ae
Showing 1 changed file with 1 addition and 5 deletions.
6 changes: 1 addition & 5 deletions doc/release-notes/10340-forbidden.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,3 @@
### API Now Returns 403 Forbidden for Permission Checks

Dataverse was returning 401 Unauthorized when a permission check failed. This has been corrected to return 403 Forbidden in these cases. That is, the API token is known to be good (401 otherwise) but the user lacks permission (403 is now sent). See also #10340 and #11116.

### Backward Incompatible Changes

See "API Now Returns 403 Forbidden for Permission Checks" above.
The [Show Role](https://dataverse-guide--11116.org.readthedocs.build/en/11116/api/native-api.html#show-role) API endpoint was returning 401 Unauthorized when a permission check failed. This has been corrected to return 403 Forbidden instead. That is, the API token is known to be good (401 otherwise) but the user lacks permission (403 is now sent). See also the [API Changelog](https://dataverse-guide--11116.org.readthedocs.build/en/11116/api/changelog.html), #10340, and #11116.

0 comments on commit a2cb8ae

Please sign in to comment.