DEV Community

Discussion on: Should routing go before security?

Collapse
 
rytis profile image
Rytis

My thoughts exactly on the security. Even though security through obscurity is not a good practice, if we return 401 for all unauthenticated requests, then we're hiding which routes exist if the user is not authenticated.

Collapse
 
jawil003 profile image
Jannik

Yeah on a security aspect it makes totally sense.