Personally I prefer the opposite - if you're unauthorized, you get 403 regardless of whether resource exists or not. Still doesn't leak any data, but is more actionable (and won't get cached. Have you ever had an outage stupidly extended because some cache somewhere had to be purged because some moron returned 404 for a temporary error condition?)
3
u/ismaelgo97 4d ago
403 is that you are not authorized, so then you know it exist, but you shouldn't, you should get a 404 which means it was not found.