A cybersecurity firm is developing a custom integration for Cortex XSOAR to interact with a partner's security appliance. The partner's API uses a unique challenge-response authentication mechanism where the integration must first request a challenge string, sign it with a pre-shared secret, and then send the signed challenge along with the original request. How should this custom authentication flow be implemented in the integration's Python code?
- ABy defining a separate utility function that generates the signed challenge for each command.
- BBy using the `demisto.credentials()` function to retrieve the challenge string.
- CBy extending the `BaseClient` class and overriding its `_http_request` method.
- DBy storing the pre-shared secret in `demisto.params()` and manually adding it to each request.
Show answer & explanationAnswer & explanation
Correct answer: C. By extending the `BaseClient` class and overriding its `_http_request` method.
Overriding the `_http_request` method of the `BaseClient` class is the most robust way to implement complex, custom authentication flows. This allows the integration to intercept every outgoing request, perform the challenge-response logic (get challenge, sign, add to headers/body), and then send the modified request, ensuring the custom authentication is applied consistently across all API calls.
Why the other options are wrong
- A. While a utility function can generate the challenge, it still needs to be explicitly called and integrated into each command, leading to code duplication. Overriding `_http_request` is more elegant and centralized.
- B. `demisto.credentials()` is for retrieving standard credentials, not for generating challenge strings or managing custom authentication logic.
- D. Storing the secret in `demisto.params()` is fine, but manually adding it to each request does not implement the challenge-response *flow* automatically.
Overriding `_http_request` for Custom Auth
Extending the `BaseClient` class in a custom integration and overriding its `_http_request` method to implement complex, non-standard authentication mechanisms (e.g., challenge-response, custom signing) that must be applied to every outgoing API call.
- Centralizes custom authentication logic.
- Ensures all requests are properly authenticated.
- Provides a hook to modify requests before sending.
Memory trick: Override the request to truly own the auth process.