2
0
mirror of https://github.com/xcat2/confluent.git synced 2026-09-28 08:10:55 +00:00

Use the csrf header name MegaRAC actually checks

The web session helper sent X-CSRF-Token. MegaRAC checks X-CSRFTOKEN, so the
login succeeded and then every request answered Invalid Authentication, which is
why this helper has never worked. Confirmed both ways against a bmc: the same
request answers 401 with the old spelling and 200 with the new one.
This commit is contained in:
Markus Hilger
2026-08-13 19:28:37 +02:00
parent 836ab7e896
commit 077c169169
@@ -168,6 +168,8 @@ class OEMHandler(generic.OEMHandler):
raise Exception('Failed to authenticate to BMC')
if 'CSRFToken' in rsp:
self.csrftok = rsp['CSRFToken']
wc.set_header('X-CSRF-Token', rsp['CSRFToken'])
# The header MegaRAC checks is spelled without separators; with
# X-CSRF-Token every subsequent call answers Invalid Authentication
wc.set_header('X-CSRFTOKEN', rsp['CSRFToken'])
self._wc = wc
return wc