<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SICF http Handler - Authorization Header not available in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785950#M1778109</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing exactly the same problem. We send a JSON JWT token in HTTP header field 'Authorization'. The token is handled by a HTTP handler class. But the 'Authorization' header field content is blanked out by SAP. When using a different name like 'AuthorizationBearer' than all works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you find a solution for this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Jack&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Mar 2016 13:08:42 GMT</pubDate>
    <dc:creator>JackGraus</dc:creator>
    <dc:date>2016-03-10T13:08:42Z</dc:date>
    <item>
      <title>SICF http Handler - Authorization Header not available</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785948#M1778107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am facing a problem with HTTP Basic Authentication Headers.&lt;/P&gt;&lt;P&gt;I have the requirement to implement Basic Authentication against a customer table. Therefore i have implemented a http handler where i want to check if the Authorization http header is set.&lt;/P&gt;&lt;P&gt;I have configured the sicf node to use an internet user an to user alternative login module sequence where i have removed the Basic Authentication module. The external breakpoint in the http handler is hit, but the authorization header is missing - even though it was set for the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can anybody tell me how i can configure the sicf/icm to pass through these http header ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 08:52:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785948#M1778107</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2013-10-15T08:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: SICF http Handler - Authorization Header not available</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785949#M1778108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First remove the Logon Data maintained for the ICF node. Have you tried the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CALL METHOD server-&amp;gt;request-&amp;gt;get_authorization&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IMPORTING&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; username = username_str&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; password = password_str.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See method AUTHENTICATION of ABAP class CL_HTTP_SERVER_NET for details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 01:19:58 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785949#M1778108</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2013-10-16T01:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: SICF http Handler - Authorization Header not available</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785950#M1778109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing exactly the same problem. We send a JSON JWT token in HTTP header field 'Authorization'. The token is handled by a HTTP handler class. But the 'Authorization' header field content is blanked out by SAP. When using a different name like 'AuthorizationBearer' than all works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you find a solution for this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Jack&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2016 13:08:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785950#M1778109</guid>
      <dc:creator>JackGraus</dc:creator>
      <dc:date>2016-03-10T13:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: SICF http Handler - Authorization Header not available</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785951#M1778110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Jack,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the kernel filters the security relevant headers.&lt;/P&gt;&lt;P&gt;I found a workaround by using X-Headers e.g. X-Username, X-Token...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2016 14:26:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sicf-http-handler-authorization-header-not-available/m-p/9785951#M1778110</guid>
      <dc:creator>martinkoch</dc:creator>
      <dc:date>2016-03-10T14:26:32Z</dc:date>
    </item>
  </channel>
</rss>

