Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security operations team is developing a custom integration for Cortex XSOAR to interact with an internal ticketing system. The ticketing system's API requires specific custom HTTP headers, such as `X-API-Key` and `X-Request-ID`, for every request. These headers are static for a given integration instance. Where should these custom headers be defined within the integration's Python code to ensure they are automatically included in all API calls made by the integration?
- AAs part of the `params` dictionary passed to `demisto.request()` for each call.
- BAs global variables outside of any class or function definition.
- CIn the `demisto.args()` dictionary at the start of each command function.
- DIn the `headers` attribute of the `BaseClient` instance.
Show answer & explanationAnswer & explanation
Correct answer: D. In the `headers` attribute of the `BaseClient` instance.
Defining custom HTTP headers in the `headers` attribute of the `BaseClient` instance within the integration's `Client` class ensures that these headers are automatically included in all subsequent HTTP requests made by that client instance, which is the standard practice for integration-wide static headers.
Why the other options are wrong
- A. Passing headers via `params` to `demisto.request()` would require explicit inclusion for every single API call, which is inefficient for static, global headers.
- B. Global variables are generally discouraged in integrations and do not automatically attach to HTTP requests; they would still need to be explicitly added.
- C. `demisto.args()` is for command-specific arguments, not integration-wide headers.
BaseClient Headers
The `headers` attribute of the `BaseClient` instance in a Cortex XSOAR custom integration where static HTTP headers (e.g., API keys, content types) are defined to be automatically included in all requests made by that client.
- Defined in the `Client` class's `BaseClient`.
- Automatically included in all HTTP requests.
- Ideal for static, integration-wide headers.
Memory trick: BaseClient's headers are the foundation of every request.