A security analyst is developing a custom integration for Cortex XSOAR that needs to interact with a partner's API. The API uses a non-standard authentication mechanism where a session token is obtained via a login endpoint and then must be included in a custom header, `X-Auth-Token`, for all subsequent requests. The token expires every 30 minutes and needs to be refreshed proactively. How should this authentication flow be implemented within the custom integration's `BaseClient`?
- ASet `self._headers = {'X-Auth-Token': 'initial_token'}` in `__init__` and manually refresh the token every 30 minutes in a separate script.
- BOverride the `_http_request` method in the `BaseClient` to fetch/refresh the token and inject it into the `X-Auth-Token` header.
- CStore the token in `demisto.setContext()` and retrieve it before each API call.
- DUse the built-in `refresh_token` parameter in the integration instance configuration.
Show answer & explanationAnswer & explanation
Correct answer: B. Override the `_http_request` method in the `BaseClient` to fetch/refresh the token and inject it into the `X-Auth-Token` header.
Overriding `_http_request` is the most robust way to handle custom, dynamic authentication schemes like proactive token refresh. This allows the integration to check token validity, refresh it if needed, and inject the current token into the required header automatically before every API call, centralizing the authentication logic.
Why the other options are wrong
- A. Setting `_headers` in `__init__` works for static headers, but doesn't handle dynamic token refreshing. A separate script would make the integration less self-contained and harder to manage.
- C. `demisto.setContext()` is for incident context, not for managing integration-level session tokens for authentication. It also doesn't handle proactive refresh.
- D. There is no built-in `refresh_token` parameter for custom integration instances that automatically handles proprietary token refresh logic; this functionality needs to be implemented within the code.
BaseClient Custom Authentication
Custom and dynamic authentication mechanisms (e.g., token refresh, custom signing) in Cortex XSOAR integrations are best implemented by overriding the `_http_request` method of the `BaseClient`.
- Centralizes authentication logic for all API calls.
- Allows dynamic header injection (e.g., `X-Auth-Token`).
- Enables proactive token refresh mechanisms.
- Ensures every request has a valid, current authentication token.
Memory trick: Override `_http_request` to orchestrate dynamic authentication.