From: Jeff King Date: Fri, 06 Feb 2026 20:44:28 GMT Subject: Re: [PATCH v3] t5550: add netrc tests for http 401/403 Message-ID: <20260206204428.GA2787536@coredump.intra.peff.net> In-Reply-To: <7583bd2c-4f2f-4a43-a36f-7e0698da8a57@ashlesh.me> On Fri, Feb 06, 2026 at 09:23:18PM +0530, Ashlesh Gawande wrote: > > > I think it is fine to check the 403 handling, but note that this _isn't_ > > > how GitHub would respond. If you try to fetch from a repository you > > > don't have access to, it will return a 401 first (so you try to log in) > > > and then a 404. The idea being to avoid revealing the existence of the > > > repository to unauthorized users. > > In the case of fine-grained access token such that the token has read > > access to the repository > > but not write access GitHub does return a 403. > > (I think this is correct behavior as the token has read access so user > > is authorized/knows about the repository). Ah, that makes sense. > So should I modify that test case to do a push instead for this specific > scenario (and update the description)? No, I think what you have is fine. From the client's perspective, they know only that they got a 403 for some reason. So there's no need for complex modeling of what the server thinks is going on. -Peff