Best practices for designing 403 error response

Viewed 30

I'm designing authorization functionality in my app and I'd like to know whether it is safe to provide details on why an access token (JWT) may have been rejected.

Possible scenarios are:

  1. JWT has expired
  2. Audience does not match
  3. Lack of necessary scopes

Should I specify the error details in the 403 response? I feel like it may give an attacker additional details about a token that he can leverage in order to break the system.

Or should it be as generic as possible, like "Authorization has failed." and that's it?

1 Answers

I agree with @VoiceOfUnreason that it's a tradeoff. For every possible error response, you should consider whether it's something that can occur from legitimate use of the app and whether the information about the error is necessary for the user/client to fix the issue. If it is, then return more details about the error. Otherwise, a generic response should be returned. In any case, you should avoid returning anything in the errors that would leak information about your system — e.g., anything that would suggest the language or framework that you use, etc.

Considering your scenarios:

  1. JWT expiration time is public information, so it's not a problem to return this info in an error. That said, I would return 401 in response to an expired JWT, as this should be a signal to the client that they should acquire a new token (either through the refresh flow or a new authorization flow).

  2. A mismatched audience is rather not something that can happen during normal usage. Here I would return a generic 403.

  3. This one is a bit more tricky. You should ask yourself why a token would contain insufficient scope. If you only have one client that you control, and you know that tokens are always requested with the correct scope, and the user can only consent to the whole scope, then I would return a generic error. On the other hand, if information about insufficient scope is necessary for the client to perform some operation to get more privileges, then you have to give that information. Sometimes, even "insufficient scope" might not be enough. You might have to be even more specific — "you need write-transaction privileges to perform this operation", etc.

Related