tyrus
  1. tyrus
  2. TYRUS-209

ServerEndpointConfig.Configurator#checkOrigin HTTP status code

    Details

    • Type: Bug Bug
    • Status: Resolved
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 1.2
    • Component/s: None
    • Labels:
      None

      Description

      If an application's configurator returns false for ServerEndpointConfig.Configurator#checkOrigin(), shouldn't the tyrus send 403 status code to client ?

      RFC says "If the server does
      not validate the origin, it will accept connections from
      anywhere. If the server does not wish to accept this
      connection, it MUST return an appropriate HTTP error code
      (e.g., 403 Forbidden) and abort the WebSocket handshake
      described in this section."

        Activity

          People

          • Assignee:
            Pavel Bucek
            Reporter:
            jitu
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: