> Auth is something different. You should return a 401 with no additional information indeed.
Yup, that's better.
> However, the point is that as an API client, you want to be able to distinguish between "this bookshelf does not contain book X" and "what are you talking about, there is no bookshelf here".
I suppose you can return a 403 if it's something you shouldn't be accessing, but then you're bleeding information. You're letting the client know that it exists, but they don't have permission to access it.
A scheme that checks for permissions first and defaults to 403 when they're insufficient regardless of the existence of the resource would work though.
I guess it depends on how you implement the entire system.