I am using following code to call one external .NET webservice which support form based authentication (asking username/pwd from browser inbuilt window). How should i call this service using HTTPRequest.
I know how to use BASIC authentication in HTTPREquest class but i dont know how to use Form Based authenication. Here is my sample code:
HttpRequest hr = new HttpRequest();
hr.setEndPoint('http://xyz/test.asmx');
hr.setMethod('POST');
String username = 'test';
String password = 'test';
Blob headerValue = Blob.valueOf(username + ':' + password);
String authorizationHeader = 'FORM ' +
EncodingUtil.base64Encode(headerValue);
hr.setHeader('Authorization', authorizationHeader);
system.debug('##### '+ authorizationHeader);
hr.setHeader('Content-Type', 'application/soap+xml');
string body = '<?xml request....xxx....';
hr.setBody(body);
hr.setTimeout(60000);
String resBody;
Http con = new Http();
HttpResponse hsp;
hsp = con.send(hr);
resBody = hsp.getBody();
system.debug('@@response='+resBody);
---------- I am getting
HTTP Error 401.2 - Unauthorized: Access is denied
Any solution?
Thanks
Aslam Bari
1 件の回答
Hi Aslam,
HttpRequest doesn't have a special "FORM" authentication scheme. The Authorization header you're creating is not a standard way to perform form-based authentication.
If the .NET service is using browser-style form authentication, you generally need to:
- Make an initial POST to the login/authentication endpoint with the username and password in the format expected by the service.
- Read the authentication cookie/token returned by that request.
- Send that cookie/token with the subsequent request to the .asmx service.
For example, if the service uses a session cookie, the flow would be:
Login request → Set-Cookie → SOAP request with Cookie header
The exact implementation depends on how the .NET application implements authentication. If you can provide the login URL and an example of the HTTP request/response from a browser or tool such as Fiddler, it should be possible to determine exactly what needs to be sent from Apex.