Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A SOC engineer is building a custom integration in Cortex XSOAR to interact with an internal ticketing system. The ticketing system's API requires specific custom headers for all requests, including an 'X-API-Key' and an 'X-Request-ID'. To ensure these headers are consistently sent with every API call made by the integration's `BaseClient`, where should these custom headers be defined in the integration's Python code?
- AIn the `__init__` method of the `BaseClient` class, passed to `BaseClient.__init__`.
- BDirectly within each `self.http_request()` call.
- CIn a global dictionary outside the `BaseClient` class and imported.
- DAs part of the `params` dictionary in the integration's YAML configuration.
Show answer & explanationAnswer & explanation
Correct answer: A. In the `__init__` method of the `BaseClient` class, passed to `BaseClient.__init__`.
To ensure custom headers are consistently sent with every API call made by an integration's `BaseClient`, they should be defined in the `__init__` method of the integration's `BaseClient` (or a subclass) and passed to the parent `BaseClient.__init__` method. This allows the BaseClient to automatically include these headers in all subsequent requests initiated by that client instance.
Why the other options are wrong
- B. Defining headers in each `self.http_request()` call is repetitive and error-prone, not ensuring consistency.
- C. While possible, a global dictionary outside the class is not the standard or most robust way to manage `BaseClient` specific headers in XSOAR integrations; the `BaseClient`'s `__init__` is designed for this.
- D. The `params` dictionary in YAML is for user-configurable integration parameters, not for defining internal `BaseClient` request headers.
BaseClient Custom Headers
Custom HTTP headers configured in the `__init__` method of an integration's `BaseClient` to be automatically included in all subsequent API requests.
- Ensures consistent header inclusion across all requests.
- Defined during client initialization.
- Centralizes header management for the client instance.
Memory trick: Initialize your client, and all headers will follow.