A security engineer is developing a custom integration that needs to interact with a partner's API. The partner requires a unique, client-specific header, `X-Partner-ID`, to be included in every API request. This ID is static and will be provided during the integration setup. How should this header be configured in the custom integration's Python code and UI to be easily managed by an administrator?
- ADefine `X-Partner-ID` as an integration instance parameter in `integration.yml` and retrieve it in the Python code.
- BHardcode the `X-Partner-ID` in the `BaseClient` `_http_request` method.
- CAdd `X-Partner-ID` as a global variable in the `demisto.py` file.
- DInstruct the administrator to manually add `X-Partner-ID` to the `additional_headers` field in the integration instance.
Show answer & explanationAnswer & explanation
Correct answer: A. Define `X-Partner-ID` as an integration instance parameter in `integration.yml` and retrieve it in the Python code.
Defining the `X-Partner-ID` as an integration instance parameter in `integration.yml` makes it configurable via the XSOAR GUI. This allows administrators to easily set and manage the ID without modifying code, while the Python code can retrieve this parameter and include it in requests, ensuring both manageability and functionality.
Why the other options are wrong
- B. Hardcoding is poor practice; it requires code changes for updates and prevents UI management.
- C. Global variables in `demisto.py` are not designed for sensitive, instance-specific configuration and lack UI configurability.
- D. While possible, forcing administrators to use a generic `additional_headers` field for a specific, mandatory parameter is less user-friendly and more error-prone than a dedicated parameter.
Configurable Integration Parameters
To allow administrators to easily manage static, integration-specific values (like custom headers) via the Cortex XSOAR UI, define them as parameters in the `integration.yml` file and access them in the Python code.
- Provides UI configurability for administrators.
- Separates configuration from code.
- Supports various input types (text, password, boolean).
Memory trick: To 'manage' your 'partner's ID', put it in the 'YAML settings'.