JavaScript is not currently enabled, but is required for full CodeSonar manual search and browse functionality.
If you are viewing this file in your hub's Web GUI, enable JavaScript in your browser: you will also need it for GUI functionality.
If you opened this file directly from disk, your browser may be directly suppressing JavaScript functionality: certain browsers perform this suppression on local files (but not files delivered by web servers) for security reasons.
| CodeSonar® 9.2p0 | CONFIDENTIAL | CodeSecure Inc |
You can use a script to find the most recent analysis of a named project.
This task provides a shell script that finds the most recent analysis of a project (specified by name), along with some suggestions for modifying the script to suit your needs.
For other scripting options, see:
The script requires that special user Anonymous has the following permissions for the project P of interest and its most recent analysis A.
See Modifying the Script for information on modifying the script to specify credentials for a non-Anonymous user with the required permissions.
The example script uses the sed, tail , and wc utilities.
Use the cURL shipped with CodeSonar: $CSONAR/third-party/curl/inst/bin/curl, where $CSONAR is the CodeSonar installation directory. Either:
The following script will download the CSV project search results for the project (or projects) on the hub specified in the first argument to the script whose name matches the second argument. It will use these results to generate a summary CSV document that lists, for each project found:
Both CSV files are stored in the directory specified in the third argument to the script.
#! /bin/sh -e
if [ $# -ne 3 ]; then
echo "Usage: $0 HUB PROJECT_NAME SAVEDIR"
exit 1
fi
HUB=$1
PROJECT_NAME=$2
SAVEDIR=$3
PROJECT_SEARCH_CSV="${HUB}/project_search.csv?query=project%3D\"${PROJECT_NAME}\"&scope=all"
CURL_CMD=curl
RESULT_FNAME=overall_results.csv
SEARCH_FNAME=project_search_results.csv
rm -fr "$SAVEDIR"
mkdir "$SAVEDIR"
cd "$SAVEDIR"
echo "project id, most recent analysis id, notes" >${RESULT_FNAME}
fetch(){
"$CURL_CMD" "$@"
}
fetch "${PROJECT_SEARCH_CSV}" -o "${SEARCH_FNAME}"
NUM_LINES=$(wc -l <"${SEARCH_FNAME}")
if [ "$NUM_LINES" -eq 1 ]; then
# If no results, report and exit.
echo "No projects with URL-encoded name '${PROJECT_NAME}' were found."
echo "This may indicate one or more of the following."
echo " - The project name was not specified correctly (remember to URL-encode)."
echo " - You do not have PROJECT_EXISTS permission for the specified project."
exit 1
fi
if [ "$NUM_LINES" -gt 2 ]; then
# If multiple results, report and keep going.
echo "Found multiple projects with URL-encoded name '${PROJECT_NAME}'."
echo "The script will attempt to report the most recent analysis of each."
fi
NO_ANALYSIS="No most recent analysis found. Either: a) the project has"
NO_ANALYSIS="${NO_ANALYSIS} no analyses or b) you do not have ANALYSIS_EXISTS"
NO_ANALYSIS="${NO_ANALYSIS} permission for the most recent analysis."
for LAST_COL in $(tail -n +2 <"${SEARCH_FNAME}" \
| sed -e 's/^.*,\([^,]*\)$/\1/')
do
RESULT_TYPE=$(echo "${LAST_COL}" \
| sed -e 's/^.*\/\(.*\)\/[0-9]\+\.csv[^,]*$/\1/')
RESULT_ID=$(echo "${LAST_COL}" \
| sed -e 's/^.*\/\([0-9]\+\)\.csv[^,]*$/\1/')
# If the last column of a result line is an analysis URL, it's the
# most recent analysis.
if test "${RESULT_TYPE}" = "analysis"
then
echo "-,${RESULT_ID},-" >>"${RESULT_FNAME}"
else
# If the last column of a result line is a project URL, the
# most recent analysis of that project cannot be reported.
if test "${RESULT_TYPE}" = "project"
then
echo "${RESULT_ID},-,${NO_ANALYSIS}" >>"${RESULT_FNAME}"
# If it's neither a project URL nor an analysis URL, report a problem.
else
echo "Unexpected result type ${RESULT_TYPE} in ${SEARCH_FNAME}."
fi
fi
done
echo "Finished: your results are in ${SAVEDIR}/${RESULT_FNAME}"
This shell script works as follows.
This is the same file you would download if you did the following.
To use this script with your hub, do the following.
| protocol | is the protocol for your hub: http or https. |
|---|---|
| host:port | is the location of your hub. |
| projname | is the name of the project whose last analysis you want to find. It must be URL-encoded. |
| savepath | is the path to the savedir directory you created in the first step. |
Using the hub at http://[::1]:7341, find the most recent analysis of the project named "My Favorite Project", saving the results in directory /tmp/csvout:
| Get more verbose output |
For more verbose curl output,
edit find_project_analysis.sh so that
curl is invoked with the
-v flag. For example:
fetch(){
"$CURL_CMD" -v "$@"
}
|
|---|---|
| No project_search_results.csv file |
If your output directory does not contain file project_search_results.csv, there are two
possible reasons.
|
| project_search_results.csv lists no results |
If your output directory contains file project_search_results.csv but it does not
list any results, there are two possibilities.
Similarly, if project_search_results.csv lists fewer results than expected, it is likely to be because Anonymous does not have PROJECT_EXISTS permission for all matching projects. |
| overall_results.csv lists project IDs rather than analysis IDs | This indicates that Anonymous has PROJECT_EXISTS permission for the project(s) of interest, but does not have ANALYSIS_EXISTS permission for the most recent analysis of each. You will need to specify credentials for a user with the required permissions. |
You may wish to make one or more of the following modifications.
To change a search to perform substring matching rather than exact
matching, we need to edit the corresponding field-condition
to change its operator from
= to :.
Because of URL-encoding, this becomes a change from %3D to %3A in the query string constructed
by the script.
PROJECT_SEARCH_CSV="${HUB}/project_search.csv?query=project%3A"${PROJECT_NAME}"&scope=all"
If your hub is configured so that special user Anonymous does not have the required permissions, you will need to edit the script to submit credentials for a suitable hub user account.
We recommend using bearer authentication. Alternative mechanisms are described in the table below.
For bearer authentication, do the following.
BEARER_TOKEN=$(cat path/to/bearerfile)
| path/to/bearerfile | is the path to the file containing the bearer token you want to use. |
|---|
fetch(){
"$CURL_CMD" -H "Authorization: Bearer ${BEARER_TOKEN}" "$@"
}
For more information about bearer authentication in CodeSonar, see User Sessions and Anonymous Sessions: Bearer Authentication.
| Certificate |
If the hub is configured for certificate-based
authentication, you can edit the script to
specify a suitable user
certificate.
|
||||
|---|---|---|---|---|---|
| Hard-Coded Username/Password |
If you will be running the shell script under secure
conditions, you may be willing to specify the account username
and password
directly in the shell script invocation.
For example, if your hub location is http://[::1]:7340 and the hub user account has username jean and password xyz123, the first argument to the shell script would be http://jean:xyz123@[::1]:7340. Example: Use the hub user account with username jean and password xyz123 to authorize finding the most recent analysis of the project named "Project X " on the hub at http://[::1]:7340, saving the results in directory/tmp/csvout:
./find_project_analysis.sh http://jean:xyz123@[::1]:7340 PROJECT%20X
/tmp/csvout
Both username and password must also be URL-encoded.
|
||||
| Username/Password: Other | See the curl man page for alternative username/password authentication mechanisms. |
See CodeSonar HTTP API: Authentication for more information on authentication strategies.
You can follow the overall structure of this script to create shell scripts that download other kinds of file from the hub.
In general, the process for constructing a script will be along the following lines.
Note. This page contains references to HTTP API documentation, which is served directly by the hub and cannot be accessed via a file:// URL. For active HTTP API documentation links, start a hub (if one is not already running), then open the manual from the hub.
To report problems with this documentation, please visit https://support.codesecure.com/.