|
|
|
The decision to not tell the client why the request was denied was deliberate - we do not want malicious clients using the information to guess attack strategies. All relevant information is contained in the server log (ie. JIRA).
If we want this to change, we need to have a discussion about exactly what information we want to publish to the client, and what we don't. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
setFailureHeader() should be either mapping InvalidRemoteAddressExceptions to a useful message, or using e.getMessage().