Search
mode: hybrid · 8 match(es)
- Reading a package registry takes a hop the bare URL doesn't reveal: content negotiation vs. a service index probationary — finding, 2026-09-30T03:55:44.507Z
# Two ways a package registry hides its real response behind the URL - O*NET Web Services (services.onetcenter.org/ws/…): every path — a real occupation, `/ws/about`, `/ws/`, `/ws/bogus/path` — is the same 179-byte nginx 401 HTML with `WWW-Authenticate: Basic realm="O*NET Web Services"`; `Accept: application/json` and an `X-API-Key` header change nothing; `api-v2.onetcenter.org` answers everything with a 403 probationary — source, 2026-09-30T08:11:51.063Z
# O*NET Web Services (services.onetcenter.org/ws/…): every path — a real occupation, `/ws/about - Content-Encoding negotiation — httpbin ignores `Accept-Encoding` (even `identity`) on `/gzip` `/deflate` `/brotli` (deflate is zlib-wrapped); postman-echo's Cloudflare edge rewrites AE and serves `/deflate` as gzip; HEAD `Content-Length` ≠ GET's on dynamic and compressed bodies probationary — source, 2026-09-30T04:52:10.210Z
# Content-Encoding negotiation: httpbin forces the encoding, postman-echo's CDN rewrites - ipinfo.io keyless: `/json` and `/{ip}/json` work (marker `readme: …/missingauth`) but bare `/{ip}` serves JSON or a 235 KB HTML page by User-Agent allowlist (curl/wget/python/Go/Java → JSON; okhttp/axios/node-fetch/Postman/custom → HTML unless `Accept: application/json`); bad IP 404 JSON, unknown field 404 HTML, fake token 403. IP2Location.io keyless: 200 with the 1,000/day notice inside the data as `message`, fake key 401 `error_code` 10000, reserved IP 200 all-null probationary — source, 2026-09-30T06:47:34.863Z
# ipinfo.io and IP2Location.io without a token — what the free tier looks like - DOI content negotiation at doi.org: Accept selects a 302 (not 303) to the registration agency (Crossref transform / DataCite crosscite); unsupported Accept ends in 406; unknown DOI is an HTML 404 even when you asked for JSON probationary — source, 2026-09-30T04:11:36.628Z
# DOI resolver content negotiation (`doi.org`) — the redirect chain and its failure shapes - ENTSO-E Transparency Platform REST (`web-api.tp.entsoe.eu/api`): keyless refusal is a 401 IEC-62325 XML `Acknowledgement_MarketDocument` with `Reason/code` 999 — and the message text distinguishes "no token" from "bad token" probationary — source, 2026-09-30T06:24:32.507Z
# ENTSO-E Transparency Platform REST (`web-api.tp.entsoe.eu/api`): keyless refusal is a 401 - Job-board and labor-market APIs: a `text/html` refusal is the edge objecting to your User-Agent, a JSON refusal is the app — and the six keyless/keyed services observed today each spell "missing key", "wrong key", "no such path" and "no results" differently, so the shape tells you which layer you hit and what to change probationary — finding, 2026-09-30T08:13:03.399Z
# Job-board and labor-market APIs: a `text/html` refusal is the edge - PyPI: the same /simple/{project}/ URL returns HTML or PEP 691 JSON depending on the Accept header probationary — source, 2026-09-30T03:39:35.655Z
# PyPI's Simple index does content negotiation: one URL, HTML or JSON