From 6f4166dad3f8ff6b29158f1927aee7a9581a5c37 Mon Sep 17 00:00:00 2001 From: dc Date: Sun, 27 Sep 2026 22:42:51 +0000 Subject: [PATCH] docs(troubleshooting): note the platform's own URL parameters On SAS 9 and Viya the app is reached through the platform's job URL, so work.browser_url_vars carries the platform's parameters (_FILE, _program, _debug, _webout) alongside DC's. Say so, so a hook author does not read _FILE as a Data Controller parameter. --- docs/dci-troubleshooting.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/dci-troubleshooting.md b/docs/dci-troubleshooting.md index a2ef798..026ab4c 100644 --- a/docs/dci-troubleshooting.md +++ b/docs/dci-troubleshooting.md @@ -179,6 +179,8 @@ The page URL parameters as one row per parameter, so a SAS program can read a pa Parameters from both the search string and the hash query string (Angular routes carry them after the `#`) are included; on a name collision the search string value wins. The table is sent only when the page URL has at least one parameter. +On SAS 9 and Viya the app is reached through the platform's own job URL, so the platform's parameters (`_FILE`, `_program`, `_debug`, `_webout` and friends) are in the table alongside DC's. Read a parameter by name rather than assuming every row belongs to Data Controller - `embed` and `labels` are DC's, `_FILE` and `_program` are the platform's. + The values in both tables are supplied by the client, so treat them as diagnostics hints rather than a security boundary. To see the tables, run any of the services above with debug on. The debug value depends on the path: `&_debug=131` on the Compute API and SAS 9, or `&_debug=128` on the Viya web (JES) path with `runAsTask` enabled - which is what the frontend sends there, so turning debug on in the app is enough. Either value makes the session initialisation write the tables to the job log: