You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Micro focus Content Manager 23.4 CMServiceAPI POST请求403错误求助

Micro Focus Content Manager 23.4 CMServiceAPI POST请求403(缺少防伪令牌)问题排查

问题描述

在开发环境测试CMServiceAPI时,所有GET请求功能正常,但POST类请求(如删除记录)均返回403错误:Could not deserialize request。

示例删除记录的curl请求:

curl -X POST --header 'Content-Type: application/x-www-form-urlencoded' --header 'Accept: application/json' -d 'DeleteRecordDeleteContents=true' 'http://servername/CMServiceAPI/Record/1/Delete'

服务器日志核心错误信息:

2024-02-20 18:19:07,861 [40] ERROR HP.HPTRIM.Service.TrimAppHost - The required anti-forgery cookie "__RequestVerificationToken_L0NNU2VydmljZUFQSQ2" is not present.
ServiceStack.HttpError: The required anti-forgery cookie "__RequestVerificationToken_L0NNU2VydmljZUFQSQ2" is not present.
at HP.HPTRIM.Service.ValidateHttpAntiForgeryToken.Execute(IRequest req, IResponse res, Object requestDto)
at HP.HPTRIM.Service.ValidateHttpAntiForgeryToken.RequestFilter(IRequest req, IResponse res, Object requestDto)
...(省略后续堆栈信息)

同时Content Manager GUI的创建、删除记录功能正常,怀疑遗漏CMServiceAPI相关配置,寻求排查方案。

排查与解决建议

1. 核心原因:防伪令牌验证机制

CMServiceAPI基于ServiceStack构建,默认启用**Anti-Forgery Token(防伪令牌)**验证,用于防范CSRF攻击:

  • GET请求无需验证令牌
  • POST/PUT/DELETE等修改类请求必须携带有效的防伪令牌(Cookie + 请求头/表单参数)
  • GUI功能正常是因为前端页面会自动获取并提交令牌,而手动curl请求未包含该令牌,触发403拦截

2. 正确携带防伪令牌的请求方式

步骤1:获取防伪Cookie

先调用任意GET接口(如获取记录列表),将响应Cookie保存到本地文件:

curl -c cookies.txt 'http://servername/CMServiceAPI/Record'

打开cookies.txt,找到类似__RequestVerificationToken_L0NNU2VydmljZUFQSQ2=xxxxxx的行,提取令牌值xxxxxx。

步骤2:携带令牌发起POST请求

有两种有效方式:

  • 方式1:携带Cookie + XSRF-TOKEN请求头
curl -X POST -b cookies.txt --header 'XSRF-TOKEN: xxxxxx' --header 'Content-Type: application/x-www-form-urlencoded' --header 'Accept: application/json' -d 'DeleteRecordDeleteContents=true' 'http://servername/CMServiceAPI/Record/1/Delete'
  • 方式2:携带Cookie + 表单参数提交令牌
curl -X POST -b cookies.txt --header 'Content-Type: application/x-www-form-urlencoded' --header 'Accept: application/json' -d 'DeleteRecordDeleteContents=true&__RequestVerificationToken=xxxxxx' 'http://servername/CMServiceAPI/Record/1/Delete'

3. 开发环境临时配置调整(可选)

若开发测试需临时禁用防伪验证,可修改CMServiceAPI的Web.config文件:

  1. 找到安装目录下的CMServiceAPI/Web.config
  2. 在<appSettings>节点添加配置:
    <!-- 允许令牌通过查询字符串传递 -->
    <add key="ServiceStack.AntiForgery.AllowTokenInQueryString" value="true" />
    <!-- 完全禁用防伪验证(生产环境禁止使用) -->
    <!-- <add key="ServiceStack.AntiForgery.ValidateToken" value="false" /> -->
    

4. 请求格式校验

确保POST请求的Content-Type与参数格式匹配:

  • 使用application/x-www-form-urlencoded时,参数需为键值对格式
  • 使用application/json时,参数需为JSON结构,令牌需放在XSRF-TOKEN请求头中

内容的提问来源于stack exchange,提问作者truezjz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 12:23:13