Yes, the trick is that you need to be logged on in PAW first (which will do the CAM logon) and then make sure you are emitting PAW:s session cookies in the request as well add the csrf cookie value as the request header 'ba-sso-authenticity'.
It might work without the request header depending on the version.
------------------------------
Christer Andersson
------------------------------