Steps to reproduce
- Login into admin area
- Call non existing admin action with ajax.
Actual result
I get 404 as expected, but why it says forbidden instead not found? In my opinion it may be confusing. Is it a bug or feature?
https://madcoders-monosnap.s3.amazonaws.com/piotr/New_Product__Products__Inventory__Products__Magento_Admin_2016-06-23_08-15-47.png