I'm coding a custom engine, but there was a step that can't be submitted, I spent a few hours to find the problem, here is what I found.
Looking at Request Headers through Chrome developer mode, found a suspected header.
data:image/s3,"s3://crabby-images/6714a/6714a3060becee5be2d33f00cf7f3d3858b6f78f" alt="Image: https://forum.gsa-online.de/uploads/editor/o8/swgwxmznltix.jpg"
Using Advanced REST Client extension to send a request.
Without x-csrf-token header // Status code: 302 Found, no page found and being redirected to login page.
![]()
data:image/s3,"s3://crabby-images/9725a/9725ae6788b526df1c521dab5c179293404de4b0" alt=""
With x-csrf-token header // Status code: 200 OK, data has been submitted successfully.
![]()
data:image/s3,"s3://crabby-images/71700/7170056244a55ebe73bd6d717a405aaa35bd01d7" alt=""
So, I want to request a command to send custom headers.
Something like this.
Something like this.
[STEP1]
modify url=...
post data=...
form request with=XMLHttpRequest
custom header=csrf-token=%csrf-token%
just download=1