Skip to main content

Intercepting Core Service traffic with Fiddler

Fiddler2 is a proxy that runs locally on your machine and stays in-between a client (i.e. typically your browser) and the remote server. It can this way intercept the communication between the two and display it in various formats.

So, in order to intercept communication with the Core Service, one should configure their Core Service client application to use the Fiddler proxy. The proxy installs itself on your local machine (when Fiddler starts), and on port 8888.

Intercepted communication shows up in Fiddler somewhat like this:

So, how do I specify a proxy in my client application? That depends on the technology used.

Java Core Service Clients

There are several ways of doing this, but the idea is that we need to set two properties:
  • http.proxyHost - the host name or IP of the proxy server (i.e. localhost for Fiddler);
  • http.proxyPort - the port the proxy is listening to (i.e. 8888 for Fiddler);
If you have access to the code, you can set them using the System.setProperty method:

      // Fiddler proxy
      System.setProperty("http.proxyHost", "localhost");
      System.setProperty("http.proxyPort", "8888");

If you have access to the JVM, set the system properties in the startup sequence of the JVM (using the -D notation):

    java -Dhttp.proxyHost=localhost -Dhttp.proxyPort=8888 ...

.Net Core Service Clients

Fiddler installs itself as default proxy and .Net uses the default system proxy by default :) So there is nothing specific you need to setup for .Net.

The only caveat is that I couldn't get it to work -- namely, the basicHttp authentication fails when communication goes through the Fiddler proxy. The following error message shows up:

The HTTP request is unauthorized with client authentication scheme 'Negotiate'. The authentication header received from the server was 'Negotiate,NTLM'.

However, I can see the authentication attempts are intercepted by Fiddler.

UPDATE: If I use wsHttp endpoint, the authentication negotiation is successful and Fiddler intercepts the communication correctly.


Comments

Popular posts from this blog

Running sp_updatestats on AWS RDS database

Part of the maintenance tasks that I perform on a MSSQL Content Manager database is to run stored procedure sp_updatestats . exec sp_updatestats However, that is not supported on an AWS RDS instance. The error message below indicates that only the sa  account can perform this: Msg 15247 , Level 16 , State 1 , Procedure sp_updatestats, Line 15 [Batch Start Line 0 ] User does not have permission to perform this action. Instead there are several posts that suggest using UPDATE STATISTICS instead: https://dba.stackexchange.com/questions/145982/sp-updatestats-vs-update-statistics I stumbled upon the following post from 2008 (!!!), https://social.msdn.microsoft.com/Forums/sqlserver/en-US/186e3db0-fe37-4c31-b017-8e7c24d19697/spupdatestats-fails-to-run-with-permission-error-under-dbopriveleged-user , which describes a way to wrap the call to sp_updatestats and execute it under a different user: create procedure dbo.sp_updstats with execute as 'dbo' as...

REL Standard Tag Library

The RSTL is a library of REL tags providing standard functionality such as iterating collections, conditionals, imports, assignments, XML XSLT transformations, formatting dates, etc. RSTL distributable is available on my Google Code page under  REL Standard Tag Library . Always use the latest JAR . This post describes each RSTL tag in the library explaining its functionality, attributes and providing examples. For understanding the way expressions are evaluated, please read my post about the  Expression Language used by REL Standard Tag Library . <c:choose> / <c:when> / <c:otherwise> Syntax:     <c:choose>         <c:when test="expr1">             Do something         </c:when>         <c:when test="expr2">             Do something else         </c:when...

Publish Binaries to Mapped Structure Groups

Today's TBB of the Week comes from the high demand in the field to publish binary assets to different mapped Structure Groups. By default SDL Tridion offers two ways of publishing binaries: All binaries publish to a folder defined in your Publication properties; All binaries rendered by a given template publish to a folder corresponding to a given Structure Group; In my view, both cases are terrible, over-simplified and not representing a real use-case. Nobody in the field wants all binaries in one folder and nobody separates binary locations by template. Instead, everybody wants a mapping mechanism that takes a binary and publishes it to a given folder, defined by a Structure Group, and this mapping is done using some kind of metadata. More often than not, the metadata is the TCM Folder location of the Multimedia Component. I have seen this implemented numerous times. So the solution to publish binaries to a given location implies finding a mapping from a TCM Folder to a...