Github answers 404 instead of a 403 when you try to access a private repository while not being logged in.
I assume the rational is to not leak information about what's private. But still, it's weird.
I assume the rational is to not leak information about what's private. But still, it's weird.
I think either approach is valid as long as you're consistent. You can make a case for either 404 or 403 when you don't have enough permissions. In GitHub's case you can argue that it's a 404 because the resource does indeed not exist through your auth context. In AWS' case you can argue that a 403 makes sense because you don't have permission to know the answer to your query.