Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A SOC engineer is updating a custom integration for Cortex XSOAR. The integration currently uses `requests.get()` to make API calls. To ensure all HTTP requests from this integration automatically include a custom `X-API-Version` header with the value `2.0`, without modifying every individual API call, which `BaseClient` method or attribute should be leveraged?
- AUse `demisto.setContext({'X-API-Version': '2.0'})` before making API calls.
- BSet `self._headers = {'X-API-Version': '2.0'}` in the `__init__` method of the `BaseClient` subclass.
- COverride the `_http_request` method in the `BaseClient` subclass to inject the header.
- DPass `headers={'X-API-Version': '2.0'}` to every `self._http_request()` call.
Show answer & explanationAnswer & explanation
Correct answer: B. Set `self._headers = {'X-API-Version': '2.0'}` in the `__init__` method of the `BaseClient` subclass.
Setting `self._headers` in the `__init__` method of a `BaseClient` subclass is the standard and most efficient way to ensure that all subsequent HTTP requests made through the `BaseClient` (via `_http_request`) automatically include common headers, avoiding the need to modify each individual call.
Why the other options are wrong
- A. `demisto.setContext` is for storing incident context, not for managing HTTP request headers.
- C. While technically possible, overriding `_http_request` for simple header injection is an overly complex solution when `self._headers` is available for this purpose.
- D. This defeats the purpose of avoiding modification of every individual API call, as it requires explicitly passing the header each time.
BaseClient Default Headers
The `BaseClient` in Cortex XSOAR allows defining default HTTP headers that are automatically included in all requests made through its `_http_request` method by setting the `self._headers` attribute.
- Configured in the `__init__` method of the `BaseClient` subclass.
- Applies to all HTTP requests made using `self._http_request`.
- Simplifies header management for common requirements.
- Headers can still be overridden by specific `_http_request` calls.
Memory trick: Init headers once to rule all requests.