Using CSRF Token from GET and Uses that in POST | 403 Forbidden | AWS Lambda

Viewed 1150

I am creating node.js function through aws lambda which makes a GET request to Hybris Market Place and gets a CSRF Token. Then I am using that token to make another POST request to post some data to Hybris Market place but I am getting an error of 403 Forbidden. Same thing works in Postman which I believe due to POSTMAN keeps GET session alive and hence CSRF token is still valid. How May I achieve that in AWS Lambda function. Below is my code. I am using promise to make two requests.

const https = require('https');

exports.handler = async (event, context, callback) => {

const tokenOptions = {
     "host": "*******.s4hana.ondemand.com",
     "path": "/sap/opu/odata/sap/***********/",
     "port": null,
     "headers":{
                 "authorization": "Basic ************=",
                 "cache-control": "no-cache",
                 "x-csrf-token": "fetch"
               },
     "method": "GET"
 };

var getToken = (tokenOptions) => {
  return new Promise((resolve,reject)=>{

        const req = https.request(tokenOptions, (res) => {

              var xToken = res.headers["x-csrf-token"];
              var sCookies = res.headers["set-cookie"];
              var response = [xToken,sCookies]
              res.on('data', () => {
                    console.log('Successfully processed HTTPS response');
                    resolve(response);
                  });
                  res.on('end', () => {
                    });
                  });
        req.on('error', function(){
            reject('Request to get token failed.');
        });
          req.end();

    });
};

    var postContent = (response) => {
      return new Promise((resolve,reject)=>{

        var options = {
          "method": "POST",
          "host": "*********-***.s4hana.ondemand.com",
          "path": "/sap/opu/odata/sap/*********/*******",
      "port":null,
      "headers":
       { "authorization": "Basic *******==",
         "x-csrf-token": response[0],
         "accept": "application/json",
         "content-type": "application/json",
         "cache-control": "no-cache",
       },
      "cookie":response[1],
      "body":
       { 
     /* Data I want to POST */
       },
      "json": true
     };


        const req = https.request(options, (res,data) => {
            console.log(res.statusCode);
                  res.on('data', () => {
                    resolve('Successfully submitted.');
                  });
                  res.on('end', () => {

                    });
                  });
        req.on('error', function(err,res){
            reject('Request to get Post failed.');
        });
        req.end();    
    });
};

getToken(tokenOptions).then((response) =>{
  console.log('Result: ' +response[0]);
  return postContent(response);
}).then((successMsg) =>{
  callback(null,successMsg);
}).catch((errMsg)=>{
  callback();
});

};
0 Answers
Related