Skip to main content
aslam bari ha fatto una domanda in #Data Management
Hi All,

 

I am using following code to call one external .NET webservice which support form based authentication (asking username/pwd from browser inbuilt window). How should i call this service using HTTPRequest.

 

I know how to use BASIC authentication in HTTPREquest class but i dont know how to use Form Based authenication. Here is my sample code:

 

HttpRequest hr = new HttpRequest();

 

            hr.setEndPoint('http://xyz/test.asmx');

 

            hr.setMethod('POST');

 

            String username = 'test';

 

            String password = 'test';

 

                      

 

            Blob headerValue = Blob.valueOf(username + ':' + password);

 

            String authorizationHeader = 'FORM ' +

 

            EncodingUtil.base64Encode(headerValue);

 

            hr.setHeader('Authorization', authorizationHeader);

 

            system.debug('##### '+ authorizationHeader);

 

            hr.setHeader('Content-Type', 'application/soap+xml');       

 

            string body = '<?xml request....xxx....';

 

            hr.setBody(body);

 

            hr.setTimeout(60000);           

 

            String resBody;

 

            Http con = new Http();

 

            HttpResponse hsp;

 

            hsp = con.send(hr);

 

            resBody = hsp.getBody();

 

            system.debug('@@response='+resBody);

 

---------- I am getting

 

HTTP Error 401.2 - Unauthorized: Access is denied

 

Any solution?

 

Thanks

 

Aslam Bari
1 risposta
  1. 23 set, 14:43

    Hi Aslam,

    HttpRequest doesn't have a special "FORM" authentication scheme. The Authorization header you're creating is not a standard way to perform form-based authentication.

    If the .NET service is using browser-style form authentication, you generally need to:

    1. Make an initial POST to the login/authentication endpoint with the username and password in the format expected by the service.
    2. Read the authentication cookie/token returned by that request.
    3. Send that cookie/token with the subsequent request to the .asmx service.

    For example, if the service uses a session cookie, the flow would be:

    Login request → Set-Cookie → SOAP request with Cookie header

    The exact implementation depends on how the .NET application implements authentication. If you can provide the login URL and an example of the HTTP request/response from a browser or tool such as Fiddler, it should be possible to determine exactly what needs to be sent from Apex. 

0/9000