mirror of
https://github.com/xcat2/confluent.git
synced 2026-09-28 08:10:55 +00:00
Use the csrf header name MegaRAC actually checks
The web session helper sent X-CSRF-Token. MegaRAC checks X-CSRFTOKEN, so the login succeeded and then every request answered Invalid Authentication, which is why this helper has never worked. Confirmed both ways against a bmc: the same request answers 401 with the old spelling and 200 with the new one.
This commit is contained in:
@@ -168,6 +168,8 @@ class OEMHandler(generic.OEMHandler):
|
||||
raise Exception('Failed to authenticate to BMC')
|
||||
if 'CSRFToken' in rsp:
|
||||
self.csrftok = rsp['CSRFToken']
|
||||
wc.set_header('X-CSRF-Token', rsp['CSRFToken'])
|
||||
# The header MegaRAC checks is spelled without separators; with
|
||||
# X-CSRF-Token every subsequent call answers Invalid Authentication
|
||||
wc.set_header('X-CSRFTOKEN', rsp['CSRFToken'])
|
||||
self._wc = wc
|
||||
return wc
|
||||
|
||||
Reference in New Issue
Block a user