From 4939c45e3d2f5ffacf4ec45b681903ee252927be Mon Sep 17 00:00:00 2001 From: John Chilton Date: Tue, 27 Jan 2015 12:14:56 -0500 Subject: [PATCH] Test cases for select validation handling. Normal selects seem to be prevented from execution with invalid parameter values, but not columns. Values are escaped properly so shell exploitation isn't the problem - but as a usability thing Galaxy should prevent execution and provide a warning message. --- test/api/test_tools.py | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/test/api/test_tools.py b/test/api/test_tools.py index 01fd30fd164..5901cad77f2 100644 --- a/test/api/test_tools.py +++ b/test/api/test_tools.py @@ -201,6 +201,27 @@ class ToolsTestCase( api.ApiTestCase ): response = self._run( "validation_default", history_id, inputs ) self._assert_status_code_is( response, 400 ) + @skip_without_tool( "multi_select" ) + def test_select_legal_values( self ): + history_id = self.dataset_populator.new_history() + inputs = { + 'select_ex': 'not_option', + } + response = self._run( "multi_select", history_id, inputs ) + self._assert_status_code_is( response, 400 ) + + @skip_without_tool( "column_param" ) + def test_column_legal_values( self ): + history_id = self.dataset_populator.new_history() + new_dataset1 = self.dataset_populator.new_dataset( history_id, content='#col1\tcol2' ) + inputs = { + 'input1': { "src": "hda", "id": new_dataset1["id"] }, + 'col': "' ; echo 'moo", + } + response = self._run( "column_param", history_id, inputs ) + # TODO: make this test pass... + self._assert_status_code_is( response, 400 ) + @skip_without_tool( "collection_paired_test" ) def test_collection_parameter( self ): history_id = self.dataset_populator.new_history()