This usage of 403 should be used carefully. It's often (probably usually) the case that you still don't want to expose existence of a resource even to an authenticated user who is not authorized to that resource. It's generally better to return 404 in that case.