For a REST API is it best practice to redirect http traffic to https or to return error with 401 or 403 status code?

Viewed 40

I have a system to system REST API which should only, always use HTTPS, but if a client sends HTTP traffic, should we redirect them to the HTTPS url, or return an error with 401 or 403 status code? I'm looking for any security best practices, and hopefully links to an explanation of why that is the best practice.

0 Answers
Related