The discussion revolves around resolving a “BAD CSRF” error when executing a PUT request using the API, curl, and PHP. hjalali initially shared their code, which was causing the error. simon suggested moving the Api-Key and Api-Username values to the request header, providing a link to a relevant topic.
Following this advice, hjalali was able to resolve the issue and shared their updated code. They also provided an additional example for updating a “user_field”.
Later, brospars inquired about when the Api-Key and Api-Username in the request header became mandatory, as their existing tool had stopped working. blake explained that support for non-HTTP header based authentication was dropped on April 6th, 2020, and provided a link to the relevant deprecation warning.
Since when it’s mandatory ?
Didn’t find it in the changelog. I made a tool 2-3 years ago to create categories in batch that worked perfectly fine and now I get this error…
Sorry about any issues this caused, we did do a slow roll out of this change and notified people the best we could, but its hard to catch every deprecation use.