An HTTP Status Code to Report Requester Impairment
ietf.org
ietf.org
>> This request code may be used to provide visibility in cases where one or more valid requests create a dangerous situation, there is a pattern of erratic requests with the potential for danger, or the requester is otherwise detected as impaired.
Why this is considered necessary is explained in the next sentence:
>> Network-controlled devices are being used for beneficial but potentially dangerous activities such as construction and remote surgery. Identifying requester impairment is important for both accurately assessing the risk a given requester presents and preventing damage caused by a high-risk requester.
> create a dangerous situation, there is a pattern of erratic requests with the potential for danger, or the requester is otherwise detected as impaired.
"The risk a given requester represents" I mean... this is just so nebulous. Is this a special status code for webserver running in a breathalyzer? I'm convinced this is some kind of post-AI satire.
To be clear I understand the need for specialized devices to prevent misuse and user error. But the HTTP protocol is like, the worst possible choice for where to build that out. This is a layer 0 concern, not layer 7.
Who knows though. Maybe in a decade when Alcohol-as-a-Service startups are delivering fine liquor directly via the built-in straw of some next-gen Oculus headset, my virtual bartender will leverage this status when they cut me off.
Eh... Seems awful indirect for an HTTP standard defined status code. Like what is it trying to say, and who could do anything about it? Sounds like wrong layer to me without more concrete details surrounding an implementation utilizing it. .
I know there's some fuzziness between the layers, but shouldn't that be squarely in the application layer?
Why would you want to announce to the client that he is tripping on a security? When erratic behaviour is detected, systems usually deny access or request more authentication.
In the second case, this seems like a nice quality of life code, but this should be mentioned in the rfc and not left for me to figure out. Besides, a more generic "please reauthenticate now" would fit better (as to not expose the reason?) or even reusing the 403 forbidden could work for this usecase.
[0] https://en.wikipedia.org/wiki/List_of_HTTP_status_codes#420
And yes, that would be way more useful.
...that sounds like an example use case for the proposed status code.
420: Requester Impaired - Infinite loop
It would allow you to signal to the requester that while their individual responses are fine, their session behavior is incoherent.
And let's be honest, it's a great name when the lowest free options are 419 or 420.
Some may roll their eyes at it, but it would certainly be a memorable status code.