Applicable to: Tungsten Import Connector 2025.1.3 and newer versions
ISSUE
When accessing the Import Connector WSDL URL: http://<server name>:25086/file/import.wsdl
the request returns: HTTP 403 Unauthorized
The Message Connector (MC) log contains the following entry:
Possible CSRF attack detected. Url=/file/import.wsdl
This behavior may affect products or integrations that retrieve the Import Connector WSDL through the HTTP endpoint, including compatibility checks and validation testing
CAUSE
This issue is an unintended side effect of security improvements introduced under:
User Story 2210646: Implement HTTP request rules to mitigate CSRF vulnerability
Accessing WSDL files through the web service interface was not considered as part of the enhancement.
Related defect: Bug 2264430 - Access to WSDL files via Http fail since TIC 2025.1.3
SOLUTION
Apply the following workaround:
After completing these steps, accessing WSDL file should return the expected WSDL content instead of an HTTP 403 Unauthorized error.
REFERENCES
User Story 2210646: Implement HTTP request rules to mitigate CSRF vulnerability
Bug 2264430: Access to WSDL files via Http fail since TIC 2025.1.3
| Product | Version | Build | Environment | Hardware |
|---|---|---|---|---|
| Kofax Import Connector |