Hi everyone,
I'm observing an odd behaviour with the JIRA cloud API when attempting to add or remove a watcher to/from an issue when the payload provided is not an accountId (ie, a username or an e-mail) as per the documents.
The documentation states that if the user provided in the payload is not found, a 404 error will be raised, which is what I'd expect to see considering I've provided a malformed payload, however, the API instead returns a 401, which states that authentication credentials are missing, which is an incorrect error code given the circumstances.
This is what a valid call would be:
curl --request DELETE '<url of the instance>/rest/api/2/issue/<issue key>/watchers?accountId=<account ID>' --user <mail>:<token>
and, as expected, that returns a 204 code.
If you have happened to provide the wrong type of data for accountId (say, an e-mail instead):
curl --request DELETE '<url of the instance>/rest/api/2/issue/<issue key>/watchers?accountId=<email>' --user <mail>:<token>
I'd expect to receive either a 404 or maybe a 400, instead I get a 401 when my credentials are, in fact, valid.