Loading...
Searching...
No Matches
getcolvals.test.4.sas
Go to the documentation of this file.
1/**
2 @file
3 @brief testing getcolvals service - input validation (security)
4 @details The libds and col in the IWANT input table must be
5 well-formed (LIBREF.DATASET and SAS name). An invalid value aborts
6 the service, which shows up as a canceled child job (an aborted
7 service registers no webout).
8
9 The payloads in tests 1-2 resolve to a REAL table / column when the
10 request content is executed as macro code, so on a vulnerable
11 service the job completes, and only the validating service cancels
12 it - the assertion cannot pass against a service that does not
13 validate.
14
15 <h4> SAS Macros </h4>
16 @li mp_assert.sas
17 @li mx_execute.sas
18 @li mf_getuniquefileref.sas
19
20**/
21
22%let _program=&appLoc/services/public/getcolvals;
23
24/**
25 * Test 1 - macro content in libds must abort the service
26 */
27%let f1=%mf_getuniquefileref();
28data _null_;
29 file &f1 termstr=crlf;
30 put 'LIBDS:$19. COL:$9.';
31 put '%sysfunc(coalescec(&dclib..MPE_X_TEST,)),SOME_TIME';
32run;
33
34%mx_execute(&_program,
35 viyacontext=&defaultcontext,
36 inputfiles=&f1:iwant,
37 outref=web1,
38 viyaresult=WEBOUT_TXT
39)
40
41%let abort1=0;
42data _null_;
43 set work.results;
44 if state='canceled' then call symputx('abort1',1);
45run;
46
47%mp_assert(
48 iftrue=(&abort1=1),
49 desc=Macro content in libds aborts the service,
50 outds=work.test_results
51)
52
53/**
54 * Test 2 - macro content in col must abort the service
55 */
56%let f2=%mf_getuniquefileref();
57data _null_;
58 file &f2 termstr=crlf;
59 put 'LIBDS:$19. COL:$9.';
60 put '&dclib..MPE_X_TEST,%sysfunc(coalescec(SOME_TIME,))';
61run;
62
63%mx_execute(&_program,
64 viyacontext=&defaultcontext,
65 inputfiles=&f2:iwant,
66 outref=web2,
67 viyaresult=WEBOUT_TXT
68)
69
70%let abort2=0;
71data _null_;
72 set work.results;
73 if state='canceled' then call symputx('abort2',1);
74run;
75
76%mp_assert(
77 iftrue=(&abort2=1),
78 desc=Macro content in col aborts the service,
79 outds=work.test_results
80)
81
82/**
83 * Test 3 - valid inputs still return values
84 */
85%let f3=%mf_getuniquefileref();
86data _null_;
87 file &f3 termstr=crlf;
88 put 'LIBDS:$19. COL:$9.';
89 put "&dclib..MPE_X_TEST,SOME_TIME";
90run;
91
92%mx_execute(&_program,
93 viyacontext=&defaultcontext,
94 inputfiles=&f3:iwant,
95 outlib=web3
96)
97
98%let nobs=0;
99proc sql noprint;
100select count(*) into: nobs from web3.vals;
101quit;
102
103%mp_assert(
104 iftrue=(&nobs>0),
105 desc=Valid inputs return values,
106 outds=work.test_results
107)
108
109/**
110 * dump results to the log for offline inspection
111 */
112data _null_;
113 set work.test_results;
114 putlog 'TEST_RESULT_LINE: ' test_result ' - ' test_description;
115run;