<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bad CSRF Token when attempting to whitelist hashes from API in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/bad-csrf-token-when-attempting-to-whitelist-hashes-from-api/m-p/381759#M2538</link>
    <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to whitelist a bulk of hashes using the Cortex XDR API (because the UI isn't working, we have an open case with support). The request always return the same error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YAlhazmi_1-1611398325577.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29649i57B65D66886D4846/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YAlhazmi_1-1611398325577.png" alt="YAlhazmi_1-1611398325577.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;400 Bad CSRF Token&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Access is denied. This server can not verify that your cross-site request forgery token belongs to your login session. Either you supplied the wrong cross-site request forgery token or your session no longer exists. This may be due to session timeout or because browser is not supplying the credentials required, as can happen when the browser has cookies turned off.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;check_csrf_token(): Invalid token&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This error ONLY shows up when we attempt to whitelist hashes. We can retrieve incidents and alerts using the same code (and hence same API key and ID) without any problem. The image below shows that it has key should be able to update the allow list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YAlhazmi_0-1611398274835.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29648iB5B9F65B8859EEEB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YAlhazmi_0-1611398274835.png" alt="YAlhazmi_0-1611398274835.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The url: "&lt;EM&gt;https://api-{domain}/public_api/v1/hash_exceptions/allow_list/&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas are appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. This is the error from the UI&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YAlhazmi_0-1611398975491.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29650iDF9D30FEF053EEF0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YAlhazmi_0-1611398975491.png" alt="YAlhazmi_0-1611398975491.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jan 2021 10:49:42 GMT</pubDate>
    <dc:creator>YAlhazmi</dc:creator>
    <dc:date>2021-01-23T10:49:42Z</dc:date>
    <item>
      <title>Bad CSRF Token when attempting to whitelist hashes from API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/bad-csrf-token-when-attempting-to-whitelist-hashes-from-api/m-p/381759#M2538</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to whitelist a bulk of hashes using the Cortex XDR API (because the UI isn't working, we have an open case with support). The request always return the same error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YAlhazmi_1-1611398325577.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29649i57B65D66886D4846/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YAlhazmi_1-1611398325577.png" alt="YAlhazmi_1-1611398325577.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;400 Bad CSRF Token&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Access is denied. This server can not verify that your cross-site request forgery token belongs to your login session. Either you supplied the wrong cross-site request forgery token or your session no longer exists. This may be due to session timeout or because browser is not supplying the credentials required, as can happen when the browser has cookies turned off.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;check_csrf_token(): Invalid token&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This error ONLY shows up when we attempt to whitelist hashes. We can retrieve incidents and alerts using the same code (and hence same API key and ID) without any problem. The image below shows that it has key should be able to update the allow list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YAlhazmi_0-1611398274835.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29648iB5B9F65B8859EEEB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YAlhazmi_0-1611398274835.png" alt="YAlhazmi_0-1611398274835.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The url: "&lt;EM&gt;https://api-{domain}/public_api/v1/hash_exceptions/allow_list/&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas are appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. This is the error from the UI&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="YAlhazmi_0-1611398975491.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29650iDF9D30FEF053EEF0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="YAlhazmi_0-1611398975491.png" alt="YAlhazmi_0-1611398975491.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 10:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/bad-csrf-token-when-attempting-to-whitelist-hashes-from-api/m-p/381759#M2538</guid>
      <dc:creator>YAlhazmi</dc:creator>
      <dc:date>2021-01-23T10:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Bad CSRF Token when attempting to whitelist hashes from API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/bad-csrf-token-when-attempting-to-whitelist-hashes-from-api/m-p/387602#M2562</link>
      <description>&lt;P&gt;I see the same behaviour&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 16:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/bad-csrf-token-when-attempting-to-whitelist-hashes-from-api/m-p/387602#M2562</guid>
      <dc:creator>kreeves</dc:creator>
      <dc:date>2021-02-24T16:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Bad CSRF Token when attempting to whitelist hashes from API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/bad-csrf-token-when-attempting-to-whitelist-hashes-from-api/m-p/388166#M2567</link>
      <description>&lt;P&gt;This is a documentation problem.&amp;nbsp; The correct path is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/public_api/v1/hash_exceptions/allowlist/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NOT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/public_api/v1/hash_exceptions/allow_list/&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 19:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/bad-csrf-token-when-attempting-to-whitelist-hashes-from-api/m-p/388166#M2567</guid>
      <dc:creator>kreeves</dc:creator>
      <dc:date>2021-02-26T19:44:51Z</dc:date>
    </item>
  </channel>
</rss>

