- If he tries to access Task #3, which is unauthorized, should I give 404 or just say he s not authorized? I get this idea from logins, whether the username is valid, I always just give a generic invalid username/password combination, to prevent the user from knowing if the user/resource exists
- If he tries to access Task #5 non-existant should I give 404? or say resource not found in a generic page?