<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: 403 Forbidden : CSRF token validation failed in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540503#M4300693</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I am facing the same issue, could you find any solution to this problem?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Osman&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 13:58:48 GMT</pubDate>
    <dc:creator>former_member706001</dc:creator>
    <dc:date>2021-05-04T13:58:48Z</dc:date>
    <item>
      <title>403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaq-p/11540497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created the Fiori app(version 1.28) in web ide and imported into eclipse.&lt;/P&gt;&lt;P&gt;In component.js config, I have mentioned the complete odata service URL without proxy and opening the application in chrome with argument --disable web security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;I Just did some Odata model binding to items aggregation of table in my xml view.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And yes, I am using OData V2 model(auto generated code in models.js), handling of csrf token is by default true.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the calls are fired one to fetch the CSRF token and the other to GET the data in a batch.&lt;/P&gt;&lt;P&gt;But still, I am facing issue that 403 Forbidden. Not able to understand why this is happening. Please find the attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/jiveimages/896187" height="276" width="307" /&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/jiveimages/896188" height="266" width="362" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly suggest If I have to do any changes either in my UI5 code, OData Service implementation or Gateway configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance..!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Best Regards,&lt;/P&gt;&lt;P&gt;Phaneendra&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 21:49:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaq-p/11540497</guid>
      <dc:creator>Private_Member_148162</dc:creator>
      <dc:date>2016-02-26T21:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540498#M4300688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="color: #333333; font-size: 12px;"&gt;Phaneendra&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly check this SCN link &lt;A __default_attr="110505" __jive_macro_name="blogpost" class="jive_macro jive_macro_blogpost" data-orig-content="Issues with CSRF token and how to solve them" href="https://community.sap.com/" modifiedtitle="true" title="Issues with CSRF token and how to solve them"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Feb 2016 07:05:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540498#M4300688</guid>
      <dc:creator>S_Sriram</dc:creator>
      <dc:date>2016-02-27T07:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540499#M4300689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sriram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply. I have already checked this blog.&lt;/P&gt;&lt;P&gt;As explained in the blog, I am not using either of them. But still I am facing the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Phaneendra.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Feb 2016 09:50:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540499#M4300689</guid>
      <dc:creator>Private_Member_148162</dc:creator>
      <dc:date>2016-02-27T09:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540500#M4300690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Phaneendra,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you checked this - &lt;A __default_attr="54896" __jive_macro_name="document" class="jive_macro_document jive_macro" data-orig-content="SAP Fiori LL16 - http 403 Forbidden CSRF token error" href="https://community.sap.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check whether in SICF service is active or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.sap.com/saphelp_uiaddon10/helpdata/en/60/5f1625c79a4dbb908b65967b9e7b15/content.htm" title="https://help.sap.com/saphelp_uiaddon10/helpdata/en/60/5f1625c79a4dbb908b65967b9e7b15/content.htm"&gt;Troubleshooting - User Interface Add-On for SAP NetWeaver - SAP Library&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;~Rahul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2016 17:37:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540500#M4300690</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-03-01T17:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540501#M4300691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;1st of all call get method for CSRF token of that service then call your upload&amp;nbsp; url.It will definitely work.Reason is very clear when we&amp;nbsp; are making any modify request(post/update method) framework validate&amp;nbsp; CSRF token(cross site request forgery) &amp;amp; making any&amp;nbsp; non modify request(get method) csrf token returns in header.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;Reward if helpful.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2016 19:43:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540501#M4300691</guid>
      <dc:creator>amarnath_prasad</dc:creator>
      <dc:date>2016-03-01T19:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540502#M4300692</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;facing the same 403 / Forbidden, although I passed CSRF token from GET to PUT. Passed also cookies and x-requested-with = ‘X’. I've described my scenario in details in responce to:&lt;/P&gt;&lt;P&gt;&lt;A href="https://blogs.sap.com/2014/07/11/issues-with-csrf-token-and-how-to-solve-them/" target="test_blank"&gt;https://blogs.sap.com/2014/07/11/issues-with-csrf-token-and-how-to-solve-them/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Would appreciate meaningful suggestions.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Ivaylo&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 17:29:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540502#M4300692</guid>
      <dc:creator>Ivaylo</dc:creator>
      <dc:date>2020-12-02T17:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540503#M4300693</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I am facing the same issue, could you find any solution to this problem?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Osman&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 13:58:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540503#M4300693</guid>
      <dc:creator>former_member706001</dc:creator>
      <dc:date>2021-05-04T13:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540504#M4300694</link>
      <description>&lt;P&gt;Hi Osman,&lt;/P&gt;&lt;P&gt;I think I workarrounded that. I redefined CL_REST_RESOURCE and its IF_REST_RESOURCE~GET method, thus escaping from CSRF cookie problem. This way I don't have any negotiation regarding CRSF, but it worked for my scenario &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Ivaylo &lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 14:41:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540504#M4300694</guid>
      <dc:creator>Ivaylo</dc:creator>
      <dc:date>2021-06-03T14:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540505#M4300695</link>
      <description>&lt;P&gt;Hello Community Friends,&lt;/P&gt;&lt;P&gt;The main thing is to pass both the previously fetched x-csrf-token itself along with its session cookie. &lt;/P&gt;&lt;P&gt;The session cookie permits to assert the validity of the x-csrf-token token. &lt;/P&gt;&lt;P&gt;You may want to have a look at the following blog post on &lt;A href="https://blogs.sap.com/2021/05/06/403-when-trying-to-create-user-with-the-scim-rest-api/" target="_blank"&gt;403&lt;/A&gt; where I discuss this matter in more &lt;A href="https://blogs.sap.com/2021/05/06/403-when-trying-to-create-user-with-the-scim-rest-api/#403-with-x-csrf-token-present" target="_blank"&gt;details&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;best regards, Piotr&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 08:53:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540505#M4300695</guid>
      <dc:creator>quovadis</dc:creator>
      <dc:date>2021-06-07T08:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540506#M4300696</link>
      <description>&lt;P&gt;This answer was really helpful. &lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 20:10:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540506#M4300696</guid>
      <dc:creator>former_member1150092</dc:creator>
      <dc:date>2021-07-13T20:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: 403 Forbidden : CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540507#M4300697</link>
      <description>&lt;P&gt;Sometimes there are also issues with the SameSite parameter settings in the backend. Check in the Browser Dev Tools if there are issues with SameSite parameter.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 12:33:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/403-forbidden-csrf-token-validation-failed/qaa-p/11540507#M4300697</guid>
      <dc:creator>former_member6142</dc:creator>
      <dc:date>2022-02-17T12:33:46Z</dc:date>
    </item>
  </channel>
</rss>

