<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: HTTP request failed (403 Forbidden): CSRF token validation failed in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaa-p/12253969#M4589120</link>
    <description>&lt;P&gt;You're welcome Prajesh!&lt;/P&gt;&lt;P&gt;If my answer helped you on finding the root cause of your issue, don't forget to mark the answer as accepted. Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 09:36:13 GMT</pubDate>
    <dc:creator>jhodel18</dc:creator>
    <dc:date>2020-09-14T09:36:13Z</dc:date>
    <item>
      <title>HTTP request failed (403 Forbidden): CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaq-p/12253966</link>
      <description>&lt;P&gt;Hey Gurus,&lt;/P&gt;
  &lt;P&gt;I'm facing this weird issue in my custom UI5 application,&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1842452-untitled.png" /&gt;&lt;/P&gt;
  &lt;P&gt;using OData model,&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1842454-untitled.png" /&gt;&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1842455-untitled.png" /&gt;&lt;/P&gt;
  &lt;P&gt;Request POST:&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1842456-untitled.png" /&gt;&lt;/P&gt;
  &lt;P&gt;Payload Error:&lt;/P&gt;
  &lt;P&gt;&lt;IMG alt="" /&gt;&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1842457-untitled.png" /&gt;&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1842458-untitled.png" /&gt;&lt;/P&gt;
  &lt;P&gt;Every thing is working fine in GW_CLIENT and POSTMAN.&lt;/P&gt;
  &lt;P&gt;Only facing issue when calling from UI5 app in chrome with disable cross.&lt;/P&gt;
  &lt;P&gt;Please help me with this, as i tried almost every thing and no luck.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 05:51:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaq-p/12253966</guid>
      <dc:creator>prajeshdesai</dc:creator>
      <dc:date>2020-09-10T05:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP request failed (403 Forbidden): CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaa-p/12253967#M4589118</link>
      <description>&lt;P&gt;Hi Prajesh,&lt;/P&gt;&lt;P&gt;I don't see any session cookies from your Request Header so it's highly likely that is the issue.&lt;/P&gt;&lt;P&gt;When testing in Postman, the tool will handle the token for you. To simulate the error in postman, before sending the POST request, try deleting the cookies and you will also get the 403 error.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 14:52:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaa-p/12253967#M4589118</guid>
      <dc:creator>jhodel18</dc:creator>
      <dc:date>2020-09-11T14:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP request failed (403 Forbidden): CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaa-p/12253968#M4589119</link>
      <description>&lt;P&gt;Thanks  &lt;SPAN class="mention-scrubbed"&gt;jhodel18&lt;/SPAN&gt;, I'm able to rectify that my cookies are blocked by chrome due to SameSite=Lax.&lt;/P&gt;&lt;P&gt;For time being I used client side workaround to resolved this,&lt;/P&gt;&lt;P&gt;Step 1: go to chrome://flags&lt;/P&gt;&lt;P&gt;Step 2: Disable &lt;STRONG&gt;SameSite by default cookies.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1842571-samesite-chrome.png" /&gt;&lt;/P&gt;&lt;P&gt;Again thanks for your great help.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 05:39:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaa-p/12253968#M4589119</guid>
      <dc:creator>prajeshdesai</dc:creator>
      <dc:date>2020-09-14T05:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP request failed (403 Forbidden): CSRF token validation failed</title>
      <link>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaa-p/12253969#M4589120</link>
      <description>&lt;P&gt;You're welcome Prajesh!&lt;/P&gt;&lt;P&gt;If my answer helped you on finding the root cause of your issue, don't forget to mark the answer as accepted. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 09:36:13 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-request-failed-403-forbidden-csrf-token-validation-failed/qaa-p/12253969#M4589120</guid>
      <dc:creator>jhodel18</dc:creator>
      <dc:date>2020-09-14T09:36:13Z</dc:date>
    </item>
  </channel>
</rss>

