mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 14:46:55 +01:00
Promote knowledge for Microsoft review skills
Move canonical knowledge for Microsoft-owned review domains into the Microsoft layer and document the skill/knowledge co-location policy. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 2a6ea875-d38e-4f30-aadb-0d606f9be231
This commit is contained in:
parent
bca8f478d8
commit
42ff075793
88 changed files with 11 additions and 7 deletions
|
|
@ -0,0 +1,10 @@
|
|||
codeunit 50100 "Order Buffer Helper"
|
||||
{
|
||||
procedure ResetStagingBuffer(var OrderBuffer: Record "Sales Header")
|
||||
begin
|
||||
// No IsTemporary check. A caller that accidentally passes the real
|
||||
// Sales Header table wipes every sales header in the company with
|
||||
// no prior warning.
|
||||
OrderBuffer.DeleteAll();
|
||||
end;
|
||||
}
|
||||
|
|
@ -0,0 +1,12 @@
|
|||
codeunit 50100 "Order Buffer Helper"
|
||||
{
|
||||
procedure ResetStagingBuffer(var OrderBuffer: Record "Sales Header")
|
||||
begin
|
||||
// The helper is designed for a temporary buffer only. Fail loudly
|
||||
// if a caller accidentally passes the real table.
|
||||
if not OrderBuffer.IsTemporary() then
|
||||
Error('ResetStagingBuffer requires a temporary Sales Header; a persistent record was passed.');
|
||||
|
||||
OrderBuffer.DeleteAll();
|
||||
end;
|
||||
}
|
||||
|
|
@ -0,0 +1,28 @@
|
|||
---
|
||||
bc-version: [all]
|
||||
domain: security
|
||||
keywords: [istemporary, deleteall, modifyall, safeguard, precondition]
|
||||
technologies: [al]
|
||||
countries: [w1]
|
||||
application-area: [all]
|
||||
---
|
||||
|
||||
# Guard bulk operations with IsTemporary
|
||||
|
||||
> Contributions welcome — open a PR to refine or extend this article.
|
||||
|
||||
## Description
|
||||
|
||||
An AL helper that accepts a `var Rec: Record X` parameter and performs a bulk operation (`DeleteAll`, `ModifyAll`, or an unfiltered loop that mutates every record) cannot tell from the signature alone whether the caller passed a temporary buffer or the real table. A misuse that passes the real table wipes or rewrites live data at production scale with no earlier warning. A single `IsTemporary` check at the procedure entry turns a silent-corruption risk into an early, actionable failure.
|
||||
|
||||
## Best Practice
|
||||
|
||||
Any helper designed to operate on a temporary record, and that performs `DeleteAll`, `ModifyAll`, or similar bulk writes on its parameter, should call `Rec.IsTemporary()` at the top and raise a descriptive error when the assumption is violated. The error message should name the parameter so the misuse is easy to locate.
|
||||
|
||||
See sample: `guard-bulk-operations-with-istemporary.good.al`.
|
||||
|
||||
## Anti Pattern
|
||||
|
||||
Trusting documentation or naming conventions alone to signal that a `var Rec` parameter is expected to be temporary. A future refactor or a copy-paste caller can pass the real table; the bulk operation then executes against production rows silently.
|
||||
|
||||
See sample: `guard-bulk-operations-with-istemporary.bad.al`.
|
||||
Loading…
Add table
Add a link
Reference in a new issue