Tungsten Automation Knowledge

HTTP 403 Unauthorized Error When Accessing /file/import.wsdl in Tungsten Import Connector

000045930 · Troubleshooting · Last Updated: Sep 9, 2026

Applicable to: Tungsten Import Connector 2025.1.3 and newer versions


ISSUE

When accessing the Import Connector WSDL URL: http://<server name>:25086/file/import.wsdl
the request returns: HTTP 403 Unauthorized

The Message Connector (MC) log contains the following entry: 
Possible CSRF attack detected. Url=/file/import.wsdl

This behavior may affect products or integrations that retrieve the Import Connector WSDL through the HTTP endpoint, including compatibility checks and validation testing

CAUSE

This issue is an unintended side effect of security improvements introduced under:
User Story 2210646: Implement HTTP request rules to mitigate CSRF vulnerability

Accessing WSDL files through the web service interface was not considered as part of the enhancement.

Related defect: Bug 2264430 - Access to WSDL files via Http fail since TIC 2025.1.3

SOLUTION

Apply the following workaround:

  1. Open the file:
    {MC Installation Folder}\xsd\Create_Config.xslt
  2. Add the following line immediately before </AllowedRequests>:
    <Rule>Target=/file/*.wsdl</Rule>
  3. Refer to the screenshot below for an example.
    WSDL.png
  4. Run the MC Configuration Tool.
  5. Restart the Message Connector.

After completing these steps, accessing WSDL file should return the expected WSDL content instead of an HTTP 403 Unauthorized error.

REFERENCES
User Story 2210646: Implement HTTP request rules to mitigate CSRF vulnerability
Bug 2264430: Access to WSDL files via Http fail since TIC 2025.1.3

Applies to

ProductVersionBuildEnvironmentHardware
Kofax Import Connector

Sections recovered from body HTML: issue, cause, solution, refs.

https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/45930 | Article 000045930 | Printed Sep 30, 2026

Back to the article · use your browser's Print command, or save the PDF.