Skip to content
Notifications
Clear all

Help: Project setup via API is failing with a cryptic 500 error

2 Posts
2 Users
0 Reactions
29 Views
(@carolp)
Reputable Member
Joined: 3 months ago
Posts: 363
Topic starter   [#11307]

Trying to automate our Checkmarx project and scan setup via their REST API. The project creation call is failing with a generic 500 Internal Server Error. No useful details in the response body.

Here's the relevant part of the script:

```bash
curl -X POST 'https://${CHECKMARX_HOST}/cxrestapi/projects'
-H 'Authorization: Bearer ${TOKEN}'
-H 'Content-Type: application/json'
-d '{
"name": "${PROJECT_NAME}",
"owningTeam": "${TEAM_ID}",
"isPublic": true
}'
```

The `TEAM_ID` is the GUID from `/cxrestapi/auth/teams`. Permissions seem correct (can create projects manually in UI). API token has `Project Manager` role.

Has anyone hit this? Need to know:
* Common causes for a 500 here?
* How to get more detailed logging from Checkmarx on API failures?
* Is the payload format wrong?

Logs on the Checkmarx server side just show the 500, no underlying exception.

—cp


—cp


   
Quote
(@carlosp)
Reputable Member
Joined: 3 months ago
Posts: 255
 

A generic 500 at the project creation endpoint, with correct permissions and a valid team GUID, often points to an issue with the payload schema or a constraint violation the API doesn't validate gracefully before hitting the database. Your payload is missing the mandatory `presetId` and `configurationId` parameters required for project creation. While the UI might use defaults, the API typically does not.

To get more detail, you need to enable debug logging on the Checkmarx service side; this usually requires a configuration change in the `log4j2.xml` file for the CxRestAPI service, setting the relevant logger to DEBUG or TRACE. Without that, you're stuck with the generic error.

You can also test by constructing a minimal, hard-coded request using a tool like Postman to eliminate any variable substitution issues in your script. Use the exact payload from the API documentation example. If that succeeds, the problem is in your variable data or formatting.


show me the SLA


   
ReplyQuote