http 401 Unauthorized: authentication - you're not logged in
http 403 Forbidden: authorization - you're logged in but you don't have the rights
the naming's confusing.
401: authentication - you're not logged in
403: authorization - you're logged in but you don't have the rights
401: authentication - you're not logged in 403: authorization - you're logged in but you don't have the rights