Loading...
Searching...
No Matches
getcols.test.sas
Go to the documentation of this file.
1/**
2 @file
3 @brief testing getcols service - input validation (security)
4 @details The libds in the IWANT input table must be a well-formed
5 LIBREF.DATASET. An invalid value aborts the service before it
6 reaches proc contents. The abort shows up as a canceled child job
7 (an aborted service registers no webout).
8
9 The payload in test 1 resolves to a REAL table when the request
10 content is executed as macro code, so on a vulnerable service the
11 job completes, and only the validating service cancels it - the
12 assertion cannot pass against a service that does not validate.
13
14 <h4> SAS Macros </h4>
15 @li mp_assert.sas
16 @li mx_execute.sas
17 @li mf_getuniquefileref.sas
18
19**/
20
21%let _program=&appLoc/services/public/getcols;
22
23/**
24 * Test 1 - macro content in libds must abort the service
25 */
26%let f1=%mf_getuniquefileref();
27data _null_;
28 file &f1 termstr=crlf;
29 put 'LIBDS:$41.';
30 put '%sysfunc(coalescec(&dclib..MPE_X_TEST,))';
31run;
32
33%mx_execute(&_program,
34 viyacontext=&defaultcontext,
35 inputfiles=&f1:iwant,
36 outref=web1,
37 viyaresult=WEBOUT_TXT
38)
39
40%let abort1=0;
41data _null_;
42 set work.results;
43 if state='canceled' then call symputx('abort1',1);
44run;
45
46%mp_assert(
47 iftrue=(&abort1=1),
48 desc=Macro content in libds aborts the service,
49 outds=work.test_results
50)
51
52/**
53 * Test 2 - valid libds still returns columns
54 */
55%let f2=%mf_getuniquefileref();
56data _null_;
57 file &f2 termstr=crlf;
58 put 'LIBDS:$41.';
59 put "&dclib..MPE_X_TEST";
60run;
61
62%mx_execute(&_program,
63 viyacontext=&defaultcontext,
64 inputfiles=&f2:iwant,
65 outlib=web2
66)
67
68%let nobs=0;
69proc sql noprint;
70select count(*) into: nobs from web2.cols;
71quit;
72
73%mp_assert(
74 iftrue=(&nobs>0),
75 desc=Valid libds returns columns,
76 outds=work.test_results
77)
78
79/**
80 * dump results to the log for offline inspection
81 */
82data _null_;
83 set work.test_results;
84 putlog 'TEST_RESULT_LINE: ' test_result ' - ' test_description;
85run;