
Attachment uploads are currently disabled. This is a temporary situation and will resume as normal in the coming days.
UNSOLVED
R
Ryan_CSULB
2 Intern
•
64 Posts
4
5736
April 5th, 2018 10:00
API Auth Changes with Recent Security Patches (anti-CSRF token)
I'm posting this to help anyone using the API and sessioncookie tokens for scripts, so you don't bang you head against the wall like I did wondering what happened. I did read the patch README and made a mental note of the IMPACTS section concerning anti-CSRF tokens and custom API work, but the note ended up getting lost in the filing cabinet. For OneFS v8.0.0.4, this concerns patch-211980, but it will affect the other versions with their similar patches as well.
Once a month I run a Perl script against the Isilon to gather basic metrics on storage use by various areas/departments and email to management. I am using Session Cookies for authentication (docu66301 - Isilon OneFS version 8.0.0 API Reference starting on page 17). It gave an "ERROR authorization required" this month. As noted in the README, I needed to take a look at https://support.emc.com/kb/517421 which describes the new requirement for a custom header (X-CSRF-Token) and a referer of the node you are running against.
In Perl I'm using the REST::Client module, so after isolating the new token, I had to add the following two headers to my calls:
$client->addHeader('X-CSRF-Token', $isicsrf);
$client->addHeader('Referer', $host);
I kept the session cookie token as a "cookie" (this didn't change):
$client->GET($cluster_stats . "?key=" . $key_ibt,{ 'Cookie'=>$isisessid });
Something to watch for:
The session cookie token is expected (or accepted) in format 'isisessid=biglongtokkenvalue' while the anti-CSRF token is required to be just the 'biglongtokenvalue' (you have to strip off the 'isicrsf=' part before assigning it to the custom header X-CSRF-Token).
I hope this helps someone.
Responses (0)
Solutions (0)
