cancel
Showing results for 
Search instead for 
Did you mean: 
Subscribe

Hi,

I have created the Fiori app(version 1.28) in web ide and imported into eclipse.

In component.js config, I have mentioned the complete odata service URL without proxy and opening the application in chrome with argument --disable web security.

I Just did some Odata model binding to items aggregation of table in my xml view.


And yes, I am using OData V2 model(auto generated code in models.js), handling of csrf token is by default true.

I can see the calls are fired one to fetch the CSRF token and the other to GET the data in a batch.

But still, I am facing issue that 403 Forbidden. Not able to understand why this is happening. Please find the attached.

Kindly suggest If I have to do any changes either in my UI5 code, OData Service implementation or Gateway configurations.

Thanks in Advance..!!

With Best Regards,

Phaneendra

View Entire Topic
quovadis
Product and Topic Expert
Product and Topic Expert

Hello Community Friends,

The main thing is to pass both the previously fetched x-csrf-token itself along with its session cookie.

The session cookie permits to assert the validity of the x-csrf-token token.

You may want to have a look at the following blog post on 403 where I discuss this matter in more details.

best regards, Piotr

Former Member
0 Likes

This answer was really helpful.