`GET /projects/:id/milestones`, `GET /groups/:id/milestones`, `GET /projects/:id/labels` and `GET /groups/:id/labels` return `401 Unauthorized` without a token, even for public projects and groups.
The neighboring read endpoints (`/issues`, `/epics`) return public data anonymously, and the web UI shows milestones and labels of public projects to anonymous visitors. The REST docs state that requests “return only public data when authentication isn’t provided”, and the milestones and labels API pages do not document an authentication requirement.
Is that expected or should I open a bug about it?
curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/groups/gitlab-org/epics?per_page=1
# 200
curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/projects/gitlab-org%2Fgitlab/issues?per_page=1
# 200
curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/groups/gitlab-org/milestones?per_page=1
# 401
curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/projects/gitlab-org%2Fgitlab/milestones?per_page=1
# 401