What's the correct header to say 'you are not authenticated/authoriz开发者_StackOverflowed to access the content of this URL, so I'm redirecting you somewhere else (eg: login page)'.
Is it fine to just use a 302 ? Or maybe a 307 ?
401 is unauthorized, there is no unauthorized and redirection (301/307) in the same HTTP status.
I'd issue a 401 with a link in the body and a timed javascript redirect.
精彩评论