Well I think that article is helpful in that what you are looking for might just be a security hole if the rest webservice can check for user credentials and let you know someone can easily bruteforce you should just know when the resource you are trying to access is not available or from the response you will get. I think if you follow the authentication part of the doc the right user should be allowed access to the resource you are trying to access or you get 403 response I guess. Thats just a suggestion though. I will experiment and let you know