That would normally be the correct answer, but the OP is "faking" a 403, not dealing with real 403's. From what I understand, the OP is using an existing script and throwing a 403 based on input. So unless the script is always called by a real 403 then this would not work (well).