From 077c169169b3d61fb74a5f1056dde0901d4f67b0 Mon Sep 17 00:00:00 2001 From: Markus Hilger Date: Thu, 13 Aug 2026 19:28:37 +0200 Subject: [PATCH] Use the csrf header name MegaRAC actually checks The web session helper sent X-CSRF-Token. MegaRAC checks X-CSRFTOKEN, so the login succeeded and then every request answered Invalid Authentication, which is why this helper has never worked. Confirmed both ways against a bmc: the same request answers 401 with the old spelling and 200 with the new one. --- confluent_server/aiohmi/redfish/oem/ami/megarac.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/confluent_server/aiohmi/redfish/oem/ami/megarac.py b/confluent_server/aiohmi/redfish/oem/ami/megarac.py index a75c09d2..a74c9b1f 100644 --- a/confluent_server/aiohmi/redfish/oem/ami/megarac.py +++ b/confluent_server/aiohmi/redfish/oem/ami/megarac.py @@ -168,6 +168,8 @@ class OEMHandler(generic.OEMHandler): raise Exception('Failed to authenticate to BMC') if 'CSRFToken' in rsp: self.csrftok = rsp['CSRFToken'] - wc.set_header('X-CSRF-Token', rsp['CSRFToken']) + # The header MegaRAC checks is spelled without separators; with + # X-CSRF-Token every subsequent call answers Invalid Authentication + wc.set_header('X-CSRFTOKEN', rsp['CSRFToken']) self._wc = wc return wc