summaryrefslogtreecommitdiffstats
path: root/application/controllers/user.php
diff options
context:
space:
mode:
authorFlorian Pritz <bluewind@xinu.at>2016-07-29 11:17:06 +0200
committerFlorian Pritz <bluewind@xinu.at>2016-07-29 11:17:06 +0200
commit2e7269f566a0204dbc83d6c8f423886e27d60363 (patch)
treecd6dc0497039b2959a8ebb2fb8ca6e510a681e3f /application/controllers/user.php
parent0db79529d129dd4fe1e9b7bf823e07510c806bd4 (diff)
Return 403 instead of 401 for missing authentication
According to the RFC this is only useful for services that use HTTP's built in authentication schemes. We don't so we can't use this code. References: https://tools.ietf.org/html/rfc7235 Signed-off-by: Florian Pritz <bluewind@xinu.at>
Diffstat (limited to 'application/controllers/user.php')
-rw-r--r--application/controllers/user.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/application/controllers/user.php b/application/controllers/user.php
index ab411d7d2..891ef9451 100644
--- a/application/controllers/user.php
+++ b/application/controllers/user.php
@@ -38,7 +38,7 @@ class User extends MY_Controller {
if ($this->muser->login($username, $password)) {
$this->output->set_status_header(204);
} else {
- $this->output->set_status_header(401);
+ $this->output->set_status_header(403);
}
}