As of today when one try to access an avatar that would generate an error (not found or forbidden) the error flow will output the regular Tuleap error page.
Not only it can lead to fancy bugs with OIDC (see art #18410) but when integrated in something that expects to have a image response, the result will be un-predicatable.