Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps, when the link could be a private repository, the error page should state it's either missing or inaccessible.

All we need is an error code 402.5 "plausible deniability between unauthorized and not found"...



The spec actually uses a 404 specifically for this purpose: http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html


Sure, and everybody who has read the spec knows that. Alas, that's 1% of your user base.

For the rest of your users it wouldn't hurt to say, "You might see something different if you're logged in." Or if they are logged in, saying, "Were you expecting something different? Maybe you just don't have access yet."


Wait, we cant hold github to account for making linkrot and not applying the spec, but when the spec is implemented by them, for good reason, say "but 1% of your user base reads the spec". Thats a bit of a double standard.


Are you talking to me? I don't think I said anything like the first half of that.


Reasonable compromise, although they'd have to use that version of the 404 page for any URL that could possibly a repository.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: