Announcement Banner
UNSOLVED

Ryan_CSULB

updated

8 years ago

R

Ryan_CSULB

2 Intern

•

64 Posts

4

5736

April 5th, 2018 10:00

API Auth Changes with Recent Security Patches (anti-CSRF token)

I'm posting this to help anyone using the API and sessioncookie tokens for scripts, so you don't bang you head against the wall like I did wondering what happened.  I did read the patch README and made a mental note of the IMPACTS section concerning anti-CSRF tokens and custom API work, but the note ended up getting lost in the filing cabinet.  For OneFS v8.0.0.4, this concerns patch-211980, but it will affect the other versions with their similar patches as well.

Once a month I run a Perl script against the Isilon to gather basic metrics on storage use by various areas/departments and email to management.  I am using Session Cookies for authentication (docu66301 - Isilon OneFS version 8.0.0 API Reference starting on page 17).  It gave an "ERROR authorization required" this month.  As noted in the README, I needed to take a look at https://support.emc.com/kb/517421 which describes the new requirement for a custom header (X-CSRF-Token) and a referer of the node you are running against.

In Perl I'm using the REST::Client module, so after isolating the new token, I had to add the following two headers to my calls:

  $client->addHeader('X-CSRF-Token', $isicsrf);

  $client->addHeader('Referer', $host);

I kept the session cookie token as a "cookie" (this didn't change):

  $client->GET($cluster_stats . "?key=" . $key_ibt,{ 'Cookie'=>$isisessid });

Something to watch for:

The session cookie token is expected (or accepted) in format 'isisessid=biglongtokkenvalue' while the anti-CSRF token is required to be just the 'biglongtokenvalue' (you have to strip off the 'isicrsf=' part before assigning it to the custom header X-CSRF-Token).

I hope this helps someone.