Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security engineer is developing a custom integration in Cortex XSOAR that interacts with a legacy system. The legacy system's API requires a specific, non-standard authentication header that includes a dynamically generated timestamp and a unique session ID. Which method should the engineer use within the integration code to correctly add this custom authentication header to every API request?
- AOverride the `_http_request` method in the `BaseClient` class to inject the header.
- BDefine the custom header in the integration instance configuration GUI.
- CUse the `params` dictionary in `BaseClient` to define the header.
- DAdd the header directly to each command's `requests.request` call.
Show answer & explanationAnswer & explanation
Correct answer: A. Override the `_http_request` method in the `BaseClient` class to inject the header.
Overriding the `_http_request` method in the `BaseClient` class allows for centralized modification of all HTTP requests made by the integration. This is ideal for adding dynamic, custom headers that apply to all API calls without repeating code in each command function.
Why the other options are wrong
- B. The integration instance configuration GUI supports standard headers, but not dynamically generated ones requiring code logic.
- C. The `params` dictionary in `BaseClient` is for URL parameters, not HTTP headers.
- D. Adding headers to each command's call is inefficient and prone to errors, especially for dynamic headers.
Custom Authentication Header Injection
To add dynamic or non-standard authentication headers to all HTTP requests within a Cortex XSOAR custom integration, override the `_http_request` method in the `BaseClient` class.
- Ensures header is present in all requests.
- Allows for dynamic header content (e.g., timestamps, session IDs).
- Centralized logic for header management.
Memory trick: HTTP requests need a central 'override' to add secret sauce.