Almost nothing inside the spec suggests in any other case, and infrequently you can't make use of a 401 in that scenario due to the fact returning a 401 is barely lawful if you incorporate a WWW-Authenticate header. Horizontal escalation is every time a hacker moves from a person consumer http://pigpgs.com