Issues vs WorkItems authentication requirements

`GET /projects/:id/milestones`, `GET /groups/:id/milestones`, `GET /projects/:id/labels` and `GET /groups/:id/labels` return `401 Unauthorized` without a token, even for public projects and groups.

The neighboring read endpoints (`/issues`, `/epics`) return public data anonymously, and the web UI shows milestones and labels of public projects to anonymous visitors. The REST docs state that requests “return only public data when authentication isn’t provided”, and the milestones and labels API pages do not document an authentication requirement.

Is that expected or should I open a bug about it?

curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/groups/gitlab-org/epics?per_page=1
# 200
 
curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/projects/gitlab-org%2Fgitlab/issues?per_page=1
# 200

curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/groups/gitlab-org/milestones?per_page=1
# 401

curl -s -o /dev/null -w '%{http_code}\n' https://gitlab.com/api/v4/projects/gitlab-org%2Fgitlab/milestones?per_page=1
# 401