<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: CSRF token validation failed in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436122#M3784875</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Suresh,&lt;/P&gt;&lt;P&gt;I tried to create entiry withou x-csrf-token and the result was 201 Created ;-).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was following the steps described in configuration for SAP NWGW:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;in SICF transaction i found my service and clicked GUI Configuration where i enter ~CHECK_CSRF_TOKEN = 0&lt;/LI&gt;&lt;LI&gt;in my request client I set up:&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;URL with path to my service + entity set&lt;/LI&gt;&lt;LI&gt;method = POST&lt;/LI&gt;&lt;LI&gt;headers:&lt;/LI&gt;&lt;/UL&gt;&lt;OL&gt;&lt;UL&gt;&lt;LI&gt;Content-Type=application/atom+xml&lt;/LI&gt;&lt;LI&gt;X-REQUESTED-WITH=XMLHTTPRequest&lt;/LI&gt;&lt;/UL&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;body with xml of created entity&lt;/LI&gt;&lt;LI&gt;authentication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that is all I need to create entity without x-csrf-token.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this information help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Aug 2014 07:49:21 GMT</pubDate>
    <dc:creator>jangold</dc:creator>
    <dc:date>2014-08-26T07:49:21Z</dc:date>
    <item>
      <title>CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaq-p/10436116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;I am getting "CSRF token validation failed " error in post method, in OData.request .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;our architecture is&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;Gateway server is common for CRM and ECC&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;Netweaver Gateway--&amp;gt;CRM,ECC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;The POST method is working for CRM services, and it is not working for case of ECC services.&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;But GET method is working for both CRM services and ECC services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;I tried by passing 'X-CSRF-Token' , but still same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;Note : IN SICF for corresponding all service i mentioned ~CHECK_CSRF_TOKEN = 0 in both systems CRM and ECC.&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;I also tried as per the index.html document in section &lt;SPAN style="font-size: 10pt; background: transparent; font-style: inherit; font-family: inherit; font-weight: inherit;"&gt;&lt;STRONG&gt;Cross-Site Request Forgery (CSRF)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit; background: transparent;"&gt; of the link&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;&lt;A _jive_internal="true" data-containerid="2056" data-containertype="14" data-objectid="50247" data-objecttype="102" href="https://answers.sap.com/docs/DOC-50247" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #3778c7;"&gt;Getting Started with Kapsel - Appendix D -- Security&lt;/A&gt; but still same problem&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-link-profile-small" data-containerid="-1" data-containertype="-1" data-objectid="455584" data-objecttype="3" href="https://answers.sap.com/people/daniel.vanleeuwen" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #3778c7;"&gt;Daniel Van Leeuwen&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 11px; font-family: inherit; color: #8b8b8b; background: transparent;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 11px; font-family: inherit; color: #8b8b8b; background: transparent;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 11px; font-family: inherit; color: #8b8b8b; background: transparent;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 11px; font-family: inherit; color: #8b8b8b; background: transparent;"&gt;Thanks in advacne&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #f8f8f8;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 11px; font-family: inherit; color: #8b8b8b; background: transparent;"&gt;Suresh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tags edited by: Michael Appleby&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 05:32:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaq-p/10436116</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-07-16T05:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436117#M3784870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try testing these services in browser rest client like postman or advanced rest client, Have you deployed these services in SMP, if yes then what is the SMP/SUP version, which native language you are using to call the services?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Abhishek Wajge &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 06:38:40 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436117#M3784870</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-07-16T06:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436118#M3784871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="color: #333333; font-size: 12px;"&gt;Abhishek Wajge&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for input,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are testing from disable-web-security chrome,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using OData.request () for post method in javascript.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I given &lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;~CHECK_CSRF_TOKEN = 0,&lt;/SPAN&gt; for all the services in SICF of Netweaver Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then service for CRM is workinf fine, But service for ECC not working&lt;/P&gt;&lt;P&gt;I&lt;SPAN style="font-size: 10pt;"&gt;n ECC we are getting "&lt;/SPAN&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;CSRF token validation failed" message.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;Is there any settings need to be done for the same in RZ10 of ECC?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;What i observed is, if i remove ~CHECK_CSRF_TOKEN = 0, then my service is working internally&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;If i call the service with relay server then it is nt working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;I am calling OData.request() to fetch the token, but i cant get the cookie from this method, which header we need to set to get the cookie. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;When i call &lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt; OData.request() with relay server URL&lt;/SPAN&gt; continuously , i am getting different CSRF tocken values .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;But if i call &lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;OData.request() with local URL, i am getting same URL for a while.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11px; color: #333333; background: #ffffff;"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="34439" data-externalid="" data-presence="null" data-userid="83109" data-username="jitendrakumar.kansal" href="https://answers.sap.com/people/jitendrakumar.kansal" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #3778c7; background: transparent;"&gt;jitendra kansal&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-link-profile-small" data-containerid="-1" data-containertype="-1" data-objectid="466095" data-objecttype="3" href="https://answers.sap.com/people/midhun.vp" style="font-size: 12px; color: #3778c7;"&gt;Midhun VP&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-link-profile-small" data-containerid="-1" data-containertype="-1" data-objectid="455584" data-objecttype="3" href="https://answers.sap.com/people/daniel.vanleeuwen" style="font-size: 12px; color: #3778c7;"&gt;Daniel Van Leeuwen&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Suresh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 07:16:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436118#M3784871</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-07-16T07:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436119#M3784872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have no experience with realy server, but I found these problem when I was using SMP server. Are you comunicating with Netweaver Gateway through SMP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post here headers of get request and response? I would like to see the cookies in response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2014 11:09:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436119#M3784872</guid>
      <dc:creator>jangold</dc:creator>
      <dc:date>2014-08-19T11:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436120#M3784873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of the Relay Server?&amp;nbsp; Also, are you using this through SMP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to recall an issue with this combination.&amp;nbsp; I believe the later patches corrected it so you might try updating each.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you want to be on SMP 2.3.4 (2.3.3 may work as well) and Relay Server 16.0.1453 or higher&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edgar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2014 18:05:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436120#M3784873</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-08-19T18:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436121#M3784874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI &lt;SPAN style="color: #333333; font-size: 12px;"&gt;Edgar&lt;/SPAN&gt;,&lt;SPAN style="color: #333333; font-size: 12px;"&gt;JG&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our architecture is gateway-----&amp;gt; ECC, CRM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the OData services of the CRM , POST method is working,&lt;/P&gt;&lt;P&gt;But OData services for ECC not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any settings, we need to do in RZ10?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;What i observed is the setting ~CHECK_CSRF_TOKEN = 0 in SICF is not working , for the services&amp;nbsp; of ECC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px; background-color: #f8f8f8;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Suresh Babu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Aug 2014 04:49:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436121#M3784874</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-08-24T04:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436122#M3784875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Suresh,&lt;/P&gt;&lt;P&gt;I tried to create entiry withou x-csrf-token and the result was 201 Created ;-).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was following the steps described in configuration for SAP NWGW:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;in SICF transaction i found my service and clicked GUI Configuration where i enter ~CHECK_CSRF_TOKEN = 0&lt;/LI&gt;&lt;LI&gt;in my request client I set up:&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;URL with path to my service + entity set&lt;/LI&gt;&lt;LI&gt;method = POST&lt;/LI&gt;&lt;LI&gt;headers:&lt;/LI&gt;&lt;/UL&gt;&lt;OL&gt;&lt;UL&gt;&lt;LI&gt;Content-Type=application/atom+xml&lt;/LI&gt;&lt;LI&gt;X-REQUESTED-WITH=XMLHTTPRequest&lt;/LI&gt;&lt;/UL&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;body with xml of created entity&lt;/LI&gt;&lt;LI&gt;authentication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that is all I need to create entity without x-csrf-token.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this information help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 07:49:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/csrf-token-validation-failed/qaa-p/10436122#M3784875</guid>
      <dc:creator>jangold</dc:creator>
      <dc:date>2014-08-26T07:49:21Z</dc:date>
    </item>
  </channel>
</rss>

