# Customer Servers Version Scan — Final Status

Date: 2026-09-17.

## Version distribution

| Version | Framework | Instances | SQL validation | PUT endpoint | ExecuteStep |
|---|---|---|---|---|---|
| **v5** (old) | ASP.NET 4.x (MVC 5.2) | 9 | ❌ NO validation | 302 (auth denied) | ✅ 202 (works!) |
| **v26.1** (new) | ASP.NET Core | 2 | ✅ "Contains invalid character" | ✅ 200 (works) | ✅ 202 (works, but SQL blocked) |
| Unknown | ? | 2 | ? | ? | ? |

## V5 servers (9 instances, 7 unique IPs)

| IP | App Path | Version |
|---|---|---|
| 198.251.74.25 | 2210JWPERKINSUAP1 | 5 |
| 198.71.52.102 | RTROGERSMBIL | 5 |
| 198.71.63.125 | CITYMARTUAPSINGLE | 5 |
| 198.71.63.125 | HuelsOilUAP1 | 3 |
| 216.250.118.44 | CASSUAP4 | 5 |
| 216.250.118.44 | RTROGERSMBIL | 5 |
| 66.175.236.165 | RTROGERSUAP1 | 5 |
| 66.175.236.165 | RTROGERSUAP3 | 5 |
| 74.208.83.171 | RTROGERSUAP1 | 5 |

## V5 ExecuteStep behavior

- Step 1: success=false, msg="not found"
- Step 2: **success=true** (executed!)
- Step 3: success=false, msg="Could not find path C:\DTN_Files\..."
- Step 4: **success=true, msg="Success"**
- Steps 5-10: empty response (no data)

## Source code analysis (from Jenkins repo)

ExecuteBrl.cs — `executeSQL` (step type 1):
```csharp
string strSQL = step.strSQL;
SqlCommand cmd = new SqlCommand(strSQL, cn);
cmd.ExecuteNonQuery();
```
**No validation! Direct SQL execution.**

ExecuteBrl.cs — `sendMail` (step type 9) → `getEmailMessage`:
```csharp
SqlDataAdapter da = new SqlDataAdapter(step.strSQL, getCS(connectionId));
da.Fill(ds);
strMessage = step.strMessage.Replace("<MESSAGE>", ds.Tables[0].Rows[0][0].ToString());
```
**No validation! SQL executed, result used in email.**

## Key finding

On v5 servers: ExecuteStep works (202), steps execute (success=true), NO SQL validation.
But: PUT endpoint returns 302 "Authorization denied" — cannot update step SQL via API.
Need: find auth mechanism for Integration API on v5 (not cookie, not basic auth).

## Next steps

1. Find auth for Integration API on v5 (maybe Windows Auth, bearer token, or API key)
2. Or: use Playwright to update step via UI (same approach as v19, but on v5 server)
3. Or: find an existing step with SQL on v5 (scan steps for strSQL != null)
