[bwcompat] send 403 on authentication errors (closes #12219849)
authorJulien Cristau <julien.cristau@logilab.fr>
Fri, 01 Apr 2016 16:50:12 +0200
changeset 11615 7e798fe70014
parent 11614 171e70a7b121
child 11616 2621daafa10c
[bwcompat] send 403 on authentication errors (closes #12219849) 200 is just wrong.
pyramid_cubicweb/bwcompat.py
--- a/pyramid_cubicweb/bwcompat.py	Fri Apr 01 16:48:14 2016 +0200
+++ b/pyramid_cubicweb/bwcompat.py	Fri Apr 01 16:50:12 2016 +0200
@@ -110,6 +110,7 @@
             # cubicweb.dbapi._NeedAuthAccessMock.
             if not content:
                 content = vreg['views'].main_template(req, 'login')
+                request.response.status_code = 403
                 request.response.body = content
         finally:
             # XXX CubicWebPyramidRequest.headers_out should