MSXML2.ServerXMLHTTP

I do not get to dabble in classic ASP much anymore, which is fine with me, but for the first time in years I had to debug some ASP code to sort out an error for someone consuming one of our web services.

The code was simple:

Set MyXmlHttp = Server.CreateObject("MSXML2.ServerXMLHTTP")
MyXmlHttp.open "get", "https://www.example.com/webservice.asmx/GetSites?StudyID=35", False
MyXmlHttp.setRequestHeader "Content-Type", "text/xml"
MyXmlHttp.send()
XmlData = MyXmlHttp.responseText

Response.Write(Server.HtmlEncode(XmlData))

And the error was:

HTTP Error 403.1 - Forbidden: Execute access is denied

Can you spot the problem?

MyXmlHttp.open "GET", "https://www.example.com/webservice.asmx/GetSites?StudyID=35", False

It might not be obvious what changed. Switching the method from "get" to "GET" fixed it.

I wondered whether this was a bug, but Microsoft's documentation confirms it is by design: for ServerXMLHTTP the method parameter is case sensitive and must be entered in all upper case letters. A lowercase verb is not recognized, and the 403.1 you get back gives no hint that the casing is the problem.