MuleSoft HTTP Connector无法接收SAP响应的Set-Cookie头
问题描述
已在MuleSoft HTTP连接器配置中启用Cookie,需从SAP服务器响应中获取Cookie和CSRF Token:
- CSRF Token可正常通过
attributes.headers.'x-csrf-token'获取 - 无法通过
message.attributes.headers.*'Set-Cookie'获取Cookie - Postman调用同一URL可同时看到Cookie和Token,SAP服务器工作正常
相关配置代码
子流程
<sub-flow name="token-subflow" doc:id="0a772e24-71fe-4496-a2c3-01f5e0a39b14" > <os:retrieve doc:name="Retrieve csrfToken" doc:id="4bd9405d-ec39-4fea-bb53-a87ed4ead6a8" key="csrfToken" target="csrfToken"> <os:default-value ><![CDATA[#[%dw 2.0 output application/json --- ""]]]></os:default-value> </os:retrieve> <choice doc:name="Choice" doc:id="83923634-0181-4ab8-a548-d7a9f72fa0a3" > <when expression='#[(Mule::p("csrf-token.disable") == "true") or isBlank(vars.csrfToken)]'> <http:request doc:name="Request for csrfToken" doc:id="90f9116f-b9a8-4bb3-9969-fa0a6e836240" config-ref="HTTP_Request_csrf_config" path="#[vars.csrfPath]"> <http:body><![CDATA[#[null]]]></http:body> <http:headers><![CDATA[#[%dw 2.0 output application/json import * from dw::core::Binaries var username = vars.baseauthUserName default "" var password = vars.baseauthPassword default "" --- { "Authorization": "Basic " ++ toBase64(username ++ ":" ++ password), "Accept": "application/xml", "X-CSRF-Token": "Fetch" }]]]></http:headers> </http:request> <set-variable value="#[%dw 2.0 output application/json --- attributes.headers.'x-csrf-token']" doc:name="Set csrfToken" doc:id="098635cb-609a-4281-8a35-06800ed22ce7" variableName="csrfToken" /> <set-variable value="#[%dw 2.0 output application/json --- // This combines all Set-Cookie items from SAP into the exact string format Postman used above (message.attributes.headers.*'Set-Cookie' default []) joinBy "; "]" doc:name="Set cookie" doc:id="43186488-458c-4d8f-99e9-7669e5a71bc3" variableName="cookie"/> <os:store doc:name="Store csrfToken" doc:id="94a65181-2fc0-4d61-b3d1-e087d2eab72d" key="csrfToken"> <os:value ><![CDATA[#[vars.csrfToken]]]></os:value> </os:store> </when> <otherwise > <logger level="DEBUG" doc:name="Retrieved csrfToken " doc:id="b9d34f37-26f8-47e1-85b1-c35b50f5375d" message="Retrieved csrfToken successfully" category="${glb.globalProperties.logging.category}"/> </otherwise> </choice> </sub-flow>
HTTP请求配置
<http:request-config name="HTTP_Request_csrf_config" doc:name="HTTP Request config" doc:id="fe1d24a3-34bb-4193-b265-497aaac6d510" basePath="${hcx-rise-csrf.basePath}" responseTimeout="${http.responseTimeOut}"> <http:request-connection protocol="HTTPS" tlsContext="TLS_Context" host="${hcx-rise-csrf.host}" port="${hcx-rise-csrf.port}"/> </http:request-config>
响应属性
org.mule.extension.http.api.HttpResponseAttributes { Status Code=200 Reason Phrase=OK Headers=[ content-type=application/xml content-length=948 // Sensitive values masked x-csrf-token=***MASKED*** // Generalized timestamps sap-metadata-last-modified=<TIMESTAMP> last-modified=<TIMESTAMP> cache-control=no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0 pragma=no-cache expires=<TIMESTAMP> dataserviceversion=2.0 // Internal SAP processing details masked sap-processing-info=***MASKED*** sap-server=true // Performance metric generalized sap-perf-fesrec=<PERF_VALUE> ] }
解决方案
1. 启用HTTP请求配置的Cookie存储
现有HTTP请求配置未显式启用Cookie存储,需添加<http:cookie-store>节点:
<http:request-config name="HTTP_Request_csrf_config" doc:name="HTTP Request config" doc:id="fe1d24a3-34bb-4193-b265-497aaac6d510" basePath="${hcx-rise-csrf.basePath}" responseTimeout="${http.responseTimeOut}"> <http:request-connection protocol="HTTPS" tlsContext="TLS_Context" host="${hcx-rise-csrf.host}" port="${hcx-rise-csrf.port}"/> <!-- 启用Cookie存储 --> <http:cookie-store /> </http:request-config>
若需持久化Cookie,可添加persistent="true"和storeId属性。
2. 调整Cookie获取方式
启用Cookie存储后,MuleSoft会自动管理Cookie,此时可通过attributes.cookies获取键值对形式的Cookie:
%dw 2.0 output application/json --- attributes.cookies // 获取所有Cookie // 或获取单个Cookie:attributes.cookies.'SESSIONID'
3. 禁用自动Cookie管理以获取原始Set-Cookie头
若需直接获取响应中的Set-Cookie头,可在<http:request>节点添加disableCookieManagement="true":
<http:request doc:name="Request for csrfToken" doc:id="90f9116f-b9a8-4bb3-9969-fa0a6e836240" config-ref="HTTP_Request_csrf_config" path="#[vars.csrfPath]" disableCookieManagement="true"> <!-- 其他配置保持不变 --> </http:request>
设置后即可通过message.attributes.headers.*'Set-Cookie'获取原始Set-Cookie头内容。
4. 调试建议
添加Logger组件输出完整响应属性,确认Cookie相关字段:
<logger level="DEBUG" doc:name="Log Full Attributes" message="#[attributes]" />
内容的提问来源于stack exchange,提问作者stewchicken
相关产品推荐
相关产品推荐

