Hi
About the http codes, that is about all the XML support pages.
If you request something and isn't logged in or the session has expired then you shouldn't get a http code 200 og a xml page with access denied.
I would suggest that you instead got a http return code 403.X