Skip to main content

#Apex Code2 人正在讨论

Hello Salesforce Developer Community, 

 

We are building a custom Apex HTTP integration to sync patient appointment schedules from our clinic web portal into Salesforce Health Cloud, but we are encountering an SSL/CORS authentication error.

 

Technical Scenario & Error: When executing an Apex HttpRequest callout from a Salesforce Sandbox to our endpoint hosted on our domain (avangartclinic.com), the system throws a System.CalloutException: Unauthorized endpoint or TLS Mutual Authentication failure.

 

Environment Details:

  • Portal Domain: avangartclinic.com
  • Salesforce Service: Health Cloud / Apex REST Callout
  • Error: TLS Handshake / CORS Origin Header Discrepancy

Steps Taken:

  1. Verified that the primary SSL certificate on avangartclinic.com is valid and fully chain-verified.
  2. Added (avangartclinic.com) to Salesforce Remote Site Settings.
  3. Tested the REST API endpoint independently via Postman (returns HTTP 200 OK).

 

Are there specific Content Security Policy (CSP) Trusted Sites configurations or certificate trust chain requirements in Salesforce Health Cloud when connecting to custom HTTPS endpoints?

 

Any advice or Apex code snippets would be greatly appreciated.

Thanks! 

 

#Apex Code

1 个回答
  1. 9月23日 16:46

    Hi @Avangart Clinic

     

    Since this is an Apex server-to-server callout, I would focus on the TLS/SSL handshake rather than CORS or CSP. CORS is primarily relevant to browser-based requests. 

    I would check the following: 

    •  Verify the endpoint in Remote Site Settings or, preferably, use a Named Credential. 
    •  Validate the complete SSL certificate chain, including all intermediate certificates. 
    •  Check that the endpoint supports the TLS version/cipher requirements expected by Salesforce. 
    •  Test the certificate chain using openssl s_client -connect avangartclinic.com:443 -showcerts. 
    •  If mutual TLS (mTLS) is being used, also verify the client certificate and its chain. 

     

    Since Postman works successfully, I would specifically compare the TLS handshake/certificate chain rather than focusing on the API response itself. 

      

    In short, I would investigate the SSL certificate chain and TLS configuration first; CSP Trusted Sites is unlikely to resolve an Apex callout TLS error. 

     

    https://help.salesforce.com/s/articleView?id=000386138&type=1&utm

     

    https://help.salesforce.com/s/articleView?id=000386840&type=1&utm_source

     

    https://help.salesforce.com/s/articleView?id=000385068&type=1&utm

     

    If you find this response helpful, please mark it as the Accepted Answer, as it may also help other Trailblazers.  

0/9000
Katie Dave 发布于 #Apex

I’ve been working a lot with Apex loops lately, and I completely agree that avoiding SOQL/DML inside loops is better for performance. Using collections like Maps for bulk processing really helps reduce governor limit risks. 

 

One thing I found especially useful is breaking down complex nested loops into smaller helper methods. It makes the code not only more efficient but also easier to maintain. 

 

I recently explored this topic in more detail and shared some practical examples of handling loops efficiently in Apex. Happy to swap notes with anyone else diving into this. 

 

#Apex  #Apex Code

0/9000