diff --git a/custom/knowledge/error-handling/table-event-subscriber-rolls-back-whole-batch.md b/custom/knowledge/error-handling/table-event-subscriber-rolls-back-whole-batch.md new file mode 100644 index 0000000..ce24bbc --- /dev/null +++ b/custom/knowledge/error-handling/table-event-subscriber-rolls-back-whole-batch.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: error-handling +keywords: [table-events, oninsert, onmodify, ondelete, transaction, rollback, commit, batch, subscriber] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/error-handling/table-event-subscriber-rolls-back-whole-batch.md +--- +# A Throw In A Table-Event Subscriber Rolls Back The Whole Batch + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +Table-trigger event subscribers (`OnAfterInsertEvent`, `OnAfterModifyEvent`, `OnAfterDeleteEvent`, and their `OnBefore` counterparts) execute synchronously inside the transaction of the write that fired them. Because AL runs on a single implicit transaction with no per-record savepoint, an error raised in such a subscriber rolls back **all work since the last `COMMIT`** — not just the record that triggered it. In a batch loop with no intermediate `COMMIT`s, a single failing record discards the entire batch. The intuition that subscriber validation fails only the current record is wrong on the BC platform. + +## Best Practice +Decide the failure granularity deliberately. If a batch must continue past individual failures, do not throw from the table-event subscriber — collect the error (for example via `ErrorInfo`/collectible errors) and let the loop continue, or isolate each record's work behind a `Codeunit.Run` / `if Codeunit.Run() then` boundary so its failure rolls back only that record. Insert intermediate `COMMIT`s only with full awareness of the durability trade-off. + +## Anti Pattern +Putting `Error`/`TestField`/`FieldError` validation inside a table-event subscriber and assuming it rejects just the offending record during bulk processing. The first failure unwinds every uncommitted record in the run, turning a one-row data problem into a whole-batch rollback. diff --git a/custom/knowledge/performance/deleteall-skips-ondelete-unless-runtrigger.md b/custom/knowledge/performance/deleteall-skips-ondelete-unless-runtrigger.md new file mode 100644 index 0000000..459ac55 --- /dev/null +++ b/custom/knowledge/performance/deleteall-skips-ondelete-unless-runtrigger.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: performance +keywords: [deleteall, ondelete, run-trigger, set-based-delete, bulk-delete, triggers, validation] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/performance/deleteall-skips-ondelete-unless-runtrigger.md +--- +# DeleteAll Skips OnDelete Unless You Pass RunTrigger + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +`Record.DeleteAll()` — equivalently `DeleteAll(false)` — translates to a single set-based SQL `DELETE` and **does not** run AL `OnDelete` triggers or field/table validations. Only database-level referential constraints still apply. To run `OnDelete` logic you must call `DeleteAll(true)`, which then deletes record-by-record and forfeits the set-based performance, making it equivalent to a `FindSet` loop calling `Delete(true)`. The common misconception, which training data reproduces, is that `DeleteAll` iterates and fires `OnDelete` per record; it does not. (Parameterless `Delete()` likewise defaults to `Delete(false)` and skips `OnDelete`.) + +## Best Practice +Use `DeleteAll()` / `DeleteAll(false)` for bulk deletion only when no AL `OnDelete` cleanup is required — it is the fast, set-based form. When `OnDelete` logic must run (cascading deletes, ledger cleanup, integration events), pass `DeleteAll(true)` and accept the row-by-row cost, or refactor the cleanup to run explicitly before the bulk delete. + +## Anti Pattern +Calling `DeleteAll()` and assuming dependent records, integration events, or validation side effects are handled by `OnDelete`. The deletion succeeds but the AL-side cleanup never runs, leaving orphaned data — and adding a manual `FindSet`/`Delete` loop "for safety" reintroduces the per-record cost the set-based form was chosen to avoid. diff --git a/custom/knowledge/security/prefer-oauth2-over-api-keys-for-external-http-calls.md b/custom/knowledge/security/prefer-oauth2-over-api-keys-for-external-http-calls.md new file mode 100644 index 0000000..234ab93 --- /dev/null +++ b/custom/knowledge/security/prefer-oauth2-over-api-keys-for-external-http-calls.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: security +keywords: [oauth2, api-key, authentication, httpclient, token-refresh] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/security/prefer-oauth2-over-api-keys-for-external-http-calls.md +--- +# Prefer OAuth2 Over API Keys For External HTTP Calls + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +External HTTP integrations from AL can authenticate using OAuth 2.0 (client-credentials for service-to-service, authorization-code for user-delegated), API keys, basic authentication, or credentials in URLs. The mechanisms differ substantially in the blast radius of a leaked secret and in how cleanly tokens can be rotated. OAuth-issued tokens expire on their own schedule and rotate cleanly; API keys and basic-auth passwords typically have to be rotated manually and usually live unencrypted in a configuration table. When the partner supports OAuth, the difference is a material security improvement, not a stylistic preference. + +## Best Practice +When the partner supports OAuth, use the platform `OAuth2` codeunit (`AcquireTokenWithClientCredentials` for service-to-service, `AcquireAuthorizationCodeTokenFromCache` for user-delegated flows) rather than hand-rolled token acquisition. Carry tokens and client secrets as `SecretText`, persist them only in IsolatedStorage (see `secrets-isolated-storage`), and refresh tokens proactively — on a buffer before the documented expiry — so routine calls never block on a token refresh. + +## Anti Pattern +Accepting an API-key or basic-auth integration because it is the first option documented, even when the partner supports OAuth. The shared secret usually ends up in a setup-table `Text` field, rotation becomes a manual operation that rarely happens, and a single disclosure exposes every tenant using the extension. diff --git a/custom/knowledge/security/secrets-isolated-storage.md b/custom/knowledge/security/secrets-isolated-storage.md new file mode 100644 index 0000000..a4e2234 --- /dev/null +++ b/custom/knowledge/security/secrets-isolated-storage.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: security +keywords: [isolatedstorage, secrets, api-key, oauth-token, connection-string, table-field, credentials] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/security/secrets-isolated-storage.md +--- +# A Secret Belongs In IsolatedStorage, Never In A Table Field + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +API keys, OAuth tokens, client secrets, and connection strings must not be stored in an ordinary table `Text` field — not even on a hidden setup table. A regular field is exposed through record reads, page display, RapidStart and Excel export, report datasets, and surfaces in `DataClassification` review; anyone with table permission can read it. The correct home is `IsolatedStorage`, which is invisible to database queries, API pages, and configuration packages. The storage-*location* decision is the rule here; how to scope and encrypt the value once it is in IsolatedStorage is covered separately. + +## Best Practice +Persist every credential with `IsolatedStorage`, write it at the point of capture, and read it only when needed. For the per-secret details — choosing the right `DataScope`, encrypting at rest, and typing the value as `SecretText` so it cannot leak into logs — follow the companion rules on IsolatedStorage `DataScope`, `SetEncrypted`, and `SecretText`. + +## Anti Pattern +A "Setup" or "Connection" table carrying a `Text` field named `API Key`, `Password`, or `Client Secret`. The value is now readable by any object with table permission, ships in RapidStart packages and Excel exports, and appears in record snapshots — a credential disclosure that no amount of encryption-in-transit elsewhere makes up for. Reviewer signal: a secret-shaped field declared on a table instead of an `IsolatedStorage` call. diff --git a/custom/knowledge/telemetry/default-telemetryscope-to-extensionpublisher.md b/custom/knowledge/telemetry/default-telemetryscope-to-extensionpublisher.md new file mode 100644 index 0000000..1b40bc6 --- /dev/null +++ b/custom/knowledge/telemetry/default-telemetryscope-to-extensionpublisher.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: telemetry +keywords: [telemetry, session-logmessage, telemetryscope, application-insights, extensionpublisher, ingestion-cost] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/telemetry/default-telemetryscope-to-extensionpublisher.md +--- +# Default TelemetryScope to ExtensionPublisher, not All + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +The `TelemetryScope` parameter of `Session.LogMessage` (and `LogError`) controls *where* a custom telemetry signal is routed, not just whether it is emitted. `TelemetryScope::ExtensionPublisher` sends the signal only to the extension publisher's own Application Insights resource. `TelemetryScope::All` sends it to **both** the publisher's resource **and** the customer's environment-level Application Insights resource. The distinction is easy to get wrong because both values compile and both "emit telemetry" — but `All` silently adds to the customer's ingestion volume and cost. Promoted to always-on: CURABIS builds telemetry-based health checks across customer environments (Wareco, Allnet, Guardique), so a scope mistake here doesn't just cost the customer — it pollutes the very signal CURABIS's own tooling reads. + +## Best Practice +Default to `TelemetryScope::ExtensionPublisher` for diagnostic telemetry that only the publisher acts on. Reserve `TelemetryScope::All` for signals the customer's own administrators are expected to monitor and act on (for example, a business event surfaced to their environment telemetry). Treat the choice as a deliberate routing decision per signal, not a copy-paste default. + +## Anti Pattern +Emitting all custom telemetry with `TelemetryScope::All` "to be safe." This pushes the publisher's internal diagnostics into every customer's Application Insights, inflating their ingestion cost and burying their own signals in noise — a footgun a code reviewer can catch by flagging `All` on any signal the customer would not act on. diff --git a/custom/knowledge/ui/factbox-design.md b/custom/knowledge/ui/factbox-design.md new file mode 100644 index 0000000..86ebbe4 --- /dev/null +++ b/custom/knowledge/ui/factbox-design.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: ui +keywords: [factbox, subpagelink, listpart, cardpart, page-part, related-information, flowfield-sift] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/ui/factbox-design.md +--- +# Filter ListPart FactBoxes With SubPageLink To The Parent Record + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +A FactBox is a page `part` that surfaces related data beside the main record so users avoid navigating away. Every FactBox runs a database query as its host page loads, so an unfiltered one is a hidden performance tax paid on every page open. The remedial trap: a `ListPart` FactBox with no `SubPageLink` does not show "the related rows" — it loads and pages through the entire source table, because nothing ties it to the host record. This makes correct `SubPageLink` linkage, not visual layout, the load-bearing design decision. + +## Best Practice +Give every `ListPart` FactBox a `SubPageLink` that maps a field on the part's source table to a `field()` of the host record (for example `SubPageLink = "Document No." = field("No.")`), so it returns only rows belonging to the current record. Prefer a `CardPart` when you only need summary figures (balance, availability, status) — it reads a single record and avoids list overhead entirely. When a FactBox shows FlowFields, ensure the calculated total is backed by a SIFT key (`MaintainSIFTIndex`) so the sum is read from the index rather than aggregated row-by-row on each load. Keep FactBox count modest and avoid heavy `OnAfterGetRecord` logic in the part. + +## Anti Pattern +Adding a `ListPart` FactBox without a `SubPageLink`, expecting it to "just show related lines." The consequence is a full-table scan on every page load that grows with the dataset and is felt worst on list pages, where the FactBox re-queries on each row selection. Reviewer signal: any `part(...)` referencing a list-type page part where the `SubPageLink` property is absent, or a FactBox FlowField filtered on non-indexed fields. A second smell is duplicating data already on the page or stacking many FactBoxes, which multiplies queries for little context gain. diff --git a/custom/knowledge/ui/fasttab-field-importance.md b/custom/knowledge/ui/fasttab-field-importance.md new file mode 100644 index 0000000..8115fb2 --- /dev/null +++ b/custom/knowledge/ui/fasttab-field-importance.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: ui +keywords: [importance, promoted, additional, fasttab, show-more, summary-line, progressive-disclosure, field-visibility] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/ui/fasttab-field-importance.md +--- +# Set Field Importance To Drive FastTab Progressive Disclosure + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +A FastTab field's `Importance` property controls whether the field is visible immediately, hidden behind "Show more", or surfaced on the collapsed FastTab header summary line. The three values are `Standard` (the default, shown in the expanded FastTab), `Promoted` (also rendered on the FastTab header when the tab is collapsed), and `Additional` (hidden until the user clicks "Show more"). Misusing these values either clutters the summary line or buries fields users need on every transaction, so reviewers should treat `Importance` as a deliberate layout decision rather than an afterthought. + +## Best Practice +Promote only the two to four identifying fields per FastTab that users must read at a glance without expanding — name, status, key amount — so the collapsed header summary line stays scannable. Leave the everyday working fields at `Standard`, and push rarely-touched fields (legacy compatibility fields, system timestamps, seldom-changed configuration) to `Additional`. Note that field-level `Importance = Promoted` is unrelated to action promotion on the page action bar; it governs FastTab field visibility only. Do not rely on initial expand or collapse state, which you cannot set programmatically and which the platform may personalize per user — design assuming any FastTab may be collapsed. + +## Anti Pattern +Setting `Importance = Promoted` on most fields of a FastTab so "everything is important" defeats progressive disclosure: the collapsed summary line overflows and conveys nothing at a glance. The opposite failure is marking frequently edited fields `Additional`, forcing users to click "Show more" on every record. A detectable signal is a FastTab whose fields are nearly all `Promoted`, or a FastTab containing only `Additional` fields, which renders as an empty tab until expanded. diff --git a/custom/knowledge/ui/page-background-tasks.md b/custom/knowledge/ui/page-background-tasks.md new file mode 100644 index 0000000..6ae0c61 --- /dev/null +++ b/custom/knowledge/ui/page-background-tasks.md @@ -0,0 +1,21 @@ +--- +bc-version: [all] +domain: ui +keywords: [enqueuebackgroundtask, async-calculation, child-session, factbox, cue-tile, onaftergetcurrrecord, responsive-page, read-only] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/ui/page-background-tasks.md +--- +# Offload Slow Read-Only Page Calculations To Background Tasks + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +Pages that compute statistics, aggregates, or external lookups inline block the page from rendering until the calculation finishes, producing a visible freeze on FactBoxes, cue tiles, and calculated fields. Business Central provides page background tasks: `CurrPage.EnqueueBackgroundTask` runs a dedicated codeunit in a read-only child session and returns values via `OnPageBackgroundTaskCompleted`, so the page opens immediately and fills in computed values as they arrive. This matters because users should never wait on a calculation they may not need. The mechanism has specific rules that are easy to get wrong, which is why it warrants an explicit pattern. + +## Best Practice +Move any noticeable read-only computation off the synchronous render path into a background task. Enqueue from `OnAfterGetCurrRecord` so the task is tied to the currently focused record, and pass small payloads through the `Dictionary of [Text, Text]` input/output, converting types with `Format` and `Evaluate`. Keep each task focused on one value or a small related set rather than one large task, and show a placeholder until results land. Because tasks auto-cancel when the page closes, the record changes, or a same-ID task is re-enqueued, always supply sensible defaults and handle the timeout path in `OnPageBackgroundTaskError` — never let critical functionality depend on completion. For tests, drive the task synchronously with `RunPageBackgroundTask`. + +## Anti Pattern +Enqueuing from `OnAfterGetRecord` on a list page fires the task for every row, and each cancels the instant the selection moves to the next row — pure wasted child-session churn; a reviewer spots `EnqueueBackgroundTask` called from `OnAfterGetRecord` (or from `OnOpenPage`, where the record context is not yet stable). The other tell is a task codeunit attempting a database write or `Modify`: background tasks run read-only and the write fails at runtime. Inline heavy calculation directly in `OnAfterGetCurrRecord` with no task at all is the baseline smell — it reintroduces the page freeze the feature exists to remove. diff --git a/custom/knowledge/ui/prefer-actionref-syntax-for-promoted-actions.md b/custom/knowledge/ui/prefer-actionref-syntax-for-promoted-actions.md new file mode 100644 index 0000000..0e2993a --- /dev/null +++ b/custom/knowledge/ui/prefer-actionref-syntax-for-promoted-actions.md @@ -0,0 +1,21 @@ +--- +bc-version: [21..] +domain: ui +keywords: [actionref, promoted-actions, area-promoted, promotedcategory, promotedonly, action-bar, legacy-syntax] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/ui/prefer-actionref-syntax-for-promoted-actions.md +--- +# Promote Actions With The Modern actionref Syntax, Never The Legacy Promoted Properties + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +Business Central 2022 release wave 2 (v21) introduced the `area(Promoted)` block with `actionref` as the way to promote page actions, separating an action's definition from its promotion. The older approach set `Promoted`, `PromotedCategory`, `PromotedOnly`, and `PromotedIsBig` directly on each action. The two syntaxes cannot be mixed within a single page or page extension, and choosing the legacy one entangles definition with presentation, making the action bar harder to maintain and to extend. Applies to new pages and page extensions on BC21 or later; existing objects already on legacy syntax are not required to be rewritten (see Anti Pattern). + +## Best Practice +For new pages and page extensions, define actions in their normal `area`, then promote selected ones with `actionref` inside `area(Promoted)`, grouping them under explicit categories such as `Category_Process` and entity-named groups. This keeps each action defined once and referenced where it should appear, supports split buttons via `ShowAs`, and lets an extension promote a base action without redefining it. When extending a page, you may use modern syntax even if the base page used legacy properties (and vice versa) — the no-mixing rule is per-object, not per-dependency-tree. + +## Anti Pattern +Setting `Promoted = true` (with `PromotedCategory`, `PromotedOnly`, or `PromotedIsBig`) on actions in new code, or attempting to combine those properties with an `area(Promoted)` block in the same object — the latter fails to compile. The reviewer signal is any `Promoted`-prefixed property on an action in a newly authored page or page extension; flag it and convert to `actionref` (VS Code offers an automated conversion). Note separately that once an action is promoted in a published app, removing the promotion is a breaking change (AS0031/AW0013), so promote conservatively rather than walking it back later. diff --git a/custom/knowledge/ui/promoted-action-groups.md b/custom/knowledge/ui/promoted-action-groups.md new file mode 100644 index 0000000..73af3e9 --- /dev/null +++ b/custom/knowledge/ui/promoted-action-groups.md @@ -0,0 +1,21 @@ +--- +bc-version: [21..] +domain: ui +keywords: [action-groups, area-promoted, actionref, showas, split-button, group-caption, navigate-group, entity-group] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/ui/promoted-action-groups.md +--- +# Use Standard Promoted Action Group Names And Placements + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +Business Central ships a fixed vocabulary of promoted action groups, and users build muscle memory around where each kind of action lives. When you define `area(Promoted)` groups, reusing the standard caption and placement for a given action class makes the page feel native; inventing your own caption or putting an action in the wrong group forces every user to relearn your page. Frontier models tend to emit plausible-but-nonstandard captions (`Go To`, `Vendor Actions`, `Related`) instead of the established BC names, which is exactly what breaks cross-page consistency — a risk that applies directly to AI-assisted AL development. + +## Best Practice +Map each action to its conventional group and use the exact standard caption: `Home`/`Process` for data-modifying and workflow actions (entity/card/document pages use `Home`, lists and worksheets use `Process`); an entity-named group (`Customer`, `Item`, `Order`) for navigation tied to the current record (statistics, ledger entries, dimensions); `Navigate` for related pages that are useful regardless of the selected record; `Report` for printing and analysis; and the workflow groups `Posting`, `Release`, `Approve`, `Request Approval`, and `Prepare` for their respective document lifecycle actions. Only `Posting` (Post / Post and Print / Preview) and `Release` (Release / Reopen) should render as split buttons via `ShowAs = SplitButton`; everything else is a normal dropdown. Within a common group keep the same action sequence you see on the matching base-app page (e.g. mirror Sales Order for a sales document) so order stays predictable. See the companion rule on `ShowAs = SplitButton` scope for the split-button decision specifically. + +## Anti Pattern +Custom captions for what is really a standard group (`Vendor Actions` instead of the `Vendor` entity group, `Go To` instead of `Navigate`), posting or statistics actions dropped into the wrong group, or many tiny one-action groups that fragment the ribbon. The reviewer signal is an `area(Promoted)` block whose `group` captions do not match the base-application names for the same page type, or a `ShowAs = SplitButton` on anything other than `Posting`/`Release`. diff --git a/custom/knowledge/upgrade/no-series-bc24-migration.md b/custom/knowledge/upgrade/no-series-bc24-migration.md new file mode 100644 index 0000000..a444da9 --- /dev/null +++ b/custom/knowledge/upgrade/no-series-bc24-migration.md @@ -0,0 +1,21 @@ +--- +bc-version: [24..] +domain: upgrade +keywords: [no-series, noseriesmanagement, codeunit-310, getnextno, peeknextno, testmanual, arerelated, no-series-batch, business-foundation, obsolete-codeunit] +technologies: [al] +countries: [w1] +application-area: [all] +extends: community/upgrade/no-series-bc24-migration.md +--- +# Migrate No. Series Calls From NoSeriesManagement To The BC24 No. Series Module + +> Contributions welcome — open a PR to refine or extend this article. + +## Description +In BC24 (2024 Wave 1) Microsoft moved number generation into the Business Foundation `No. Series` codeunit (310) and obsoleted the legacy `NoSeriesManagement` codeunit (396). Code that still declares `Codeunit NoSeriesManagement` or calls its methods compiles only against the temporary obsolete shim and will break once Microsoft removes it. The new API is not a drop-in rename: the facade exposes a small, specific set of real methods, parameter shapes changed, and the old single method that both previewed and consumed a number was split into two. Getting the mapping wrong silently consumes numbers when you only meant to preview, leaving gaps in the sequence. Applies to projects on BC24 or later; on earlier versions `NoSeriesManagement` remains the correct API. + +## Best Practice +Replace the `NoSeriesManagement` variable with `Codeunit "No. Series"` and map each call deliberately using the facade's actual methods — `GetNextNo`, `PeekNextNo`, `GetLastNoUsed`, `TestManual`, `IsManual`, and `AreRelated`. Use `GetNextNo(SeriesCode, RefDate)` only when you intend to consume and advance the series for a committed document, and `PeekNextNo(SeriesCode, RefDate)` for any display, validation, or preview-posting path where you must not consume. Replace `InitSeries` with a guarded `if "No." = '' then "No." := NoSeries.GetNextNo(...)`. Map `SelectSeries` to `LookupRelatedNoSeries`, relationship checks the old code did by hand to `AreRelated`, and both `TestManual` and `ManualNoAllowed` to `TestManual` (which now raises its own error). For multi-document allocation use `Codeunit "No. Series - Batch"` and persist its state once with `SaveState` instead of committing per iteration. + +## Anti Pattern +Mechanically swapping the codeunit reference while keeping the old boolean call shape. The legacy `GetNextNo(Series, Date, false)` meant "peek" and `GetNextNo(Series, Date, true)` meant "consume"; the new `GetNextNo` always consumes and takes no boolean. Equally common is inventing validation helpers such as `IsValidNo`, `VerifySeriesExists`, `IsValidForDate`, or `TryGetNextNo` — these names are not on the `No. Series` or `No. Series - Batch` codeunits and will not compile, a frequent LLM hallucination for this migration. A reviewer can detect the defect by the residual third boolean argument, by any lingering `NoSeriesMgt`/`NoSeriesManagement` identifier, by a fabricated method name, or by an `OnBeforeGetNextNo`/`OnAfterGetNextNo` subscriber — those events were removed without replacement, so that logic must be rewritten as inline pre/post procedures, not re-subscribed. A subtler signal is `GetNextNo` used merely to display a preview, which silently advances the series and creates number gaps; that should be `PeekNextNo`.