Indeed it appears that it does.
- If the object could not be added to the collection, for example due to the privacy settings configured by its owner, the server SHOULD either respond with
403 Unauthorized
or respond with200 OK
and later send aReject{Create}
activity to the originating server.