The expected client behavior is sending in return an empty http post request with wtf header and value "I feel this server is passive aggressive towards me."
The expected client behavior is sending in return an empty http post request with wtf header and value "I feel this server is passive aggressive towards me."
From the examples, this seem to be the point. If you receive a 429, you know you can just backoff a bit and it'll work at a later point, but if you receive 999, you're not sure how to proceed, which seems to be what they (the service) wants.
Given that this seems to be bot-protection, that might actually be the point. It's basically saying; "I don't want you here, don't try to resolve this". Or in other words "F*ck off"
Other options for this case:
403 Forbidden is probably the best fit. "The 403 (Forbidden) status code indicates that the server understood the request but refuses to fulfill it."
But it may not sufficiently communicate the "go away forever" aspect. Alternatives might include:
410 (maybe its not actually, strictly gone, but I'm never going to give it to you, so stop asking) Has the benefit of also being a 4xx error so focuses on it being a client error.
301 Moved Permanently Location: file:///dev/null
IMO, it should be a simple 403 Forbidden.
And there's really no limit. If I'm going to be nonstandard, I could use more than three digits in the error code. I could use hex. I could use full text. The possibilities are limitless.