Ten Stars

csrf tokens and web files

Has anyone had any experience authenticating with a web page that uses csrf tokens?  I had a job break after a web site update, and the culprit seems to be these tokens.  I managed to parse the web page and extract the token value on the login page, but including that value with my POST request doesn't seem to be working.

1 ACCEPTED SOLUTION

Accepted Solutions
Ten Stars

Re: csrf tokens and web files

So I worked out what was missing. When downloading the page to extract the token, I needed to also store a cookie. Then when authenticating, I both read and saved that cookie. After authenticating, subsequent tFileFetch components worked by just reading the cookie. No need to reference the token.
1 REPLY
Ten Stars

Re: csrf tokens and web files

So I worked out what was missing. When downloading the page to extract the token, I needed to also store a cookie. Then when authenticating, I both read and saved that cookie. After authenticating, subsequent tFileFetch components worked by just reading the cookie. No need to reference the token.