• 2 Posts
  • 13 Comments
Joined 1 year ago
cake
Cake day: July 16th, 2023

help-circle


  • to be even more pedantic, if we follow the relevant official RFCs for http (formerly 2616, but now 7230-7235 which have relevant changes), a 403 can substitute for a 401, but a 401 has specific requirements:

    The server generating a 401 response MUST send a WWW-Authenticate header field (Section 4.1) containing at least one challenge applicable to the target resource.

    (the old 2616 said 403 must not respond with a request for authentication but the new versions don’t seem to mention that)







  • it’s replicable and “atomic”, which for a well-designed modern package manager shouldn’t be that noticable of a difference, but when it’s applied to an operating system a la nixos, you can (at least in theory) copy your centralized exact configuration to another computer and get an OS that behaves exactly the same and has all the same packages. And backup the system state with only a few dozen kilobytes of config files instead of having to backup the entire hard drive (well, assuming the online infrastructure needed to build it in the first place continues to work as expected), and probably rollback a bad change much easier



  • The same comment touches on several topics, replying to 2 different people. These two statements being in the same comment is not evidence of them being about the same thing, and if the author expected readers to get that from it, it is absolutely the author’s fault if their words got misinterpreted.

    And in the next paragraph:

    We importantly chose not to call anyone out by name in the there because our expectations aren’t about one person. All of us need to be aware of what is and isn’t okay and a lot of people were involved in the problematic threads, even if Tim, as self-identified here, was one big part

    Again referring to multiple people.