← 문제 라이브러리
Security Beginner 3 min

403 Forbidden: login works but one admin action is refused (vs 401)

Tell authentication failures (401) from authorization failures (403).

무료
시나리오

A new operator can log in and list users (GET /api/users → 200), but POST /api/users/1042/lock returns 403 Forbidden with {"message":"requires role: user-admin"}.

먼저 볼 것
  • Understand the main investigation order for Security incidents.
  • Separate user-facing symptoms from the deeper technical cause.
  • Describe both quick recovery actions and follow-up improvements.
점검 체크리스트
  1. Summarize the symptom and the current impact first.
  2. Check recent changes before collecting deeper diagnostics.
  3. Verify config, runtime state, and recovery path in order.
복구와 재발 방지

Write down the minimal recovery path first, then capture the improvements that reduce repeat incidents.

같이 보면 좋은 질문
Should I translate commands, logs, or product names?

No. Keep commands, logs, file names, APIs, and product names unchanged, then explain the reasoning in the selected UI language.

What should the answer focus on?

State the root cause, the evidence that supports it, and the safest recovery direction.

Why can the scenario remain in the original language?

The source scenario is treated as an incident artifact. Guidance, checklist, hints, and explanations can be localized around it.