mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 14:46:55 +01:00
Scope DataClassification inheritance to fields declared in the table
Table-level DataClassification is the effective default only for Normal fields declared inside that table object. A tableextension cannot set the property (AL0246) and its added fields do not inherit the base table value, so AS0016 still requires each of them to classify itself. State this in both privacy articles so the guidance cannot suppress genuine findings on the tableextension pattern, which is how most partner code adds fields. Also narrow the inheritance claim to verified AppSourceCop behaviour rather than asserting platform-level resolution, and make the sample's table-level default semantically representative of its fields while keeping a legitimate field-level override and demonstrating the tableextension boundary. Verified with alc.exe 18.0.37.11445 + Microsoft.Dynamics.Nav.AppSourceCop.dll: the revised sample produces no AS0016, and removing the explicit classification from the tableextension field makes AS0016 fire. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
parent
a668920e96
commit
f8acb6cbdd
3 changed files with 26 additions and 13 deletions
|
|
@ -11,7 +11,7 @@ application-area: [all]
|
|||
|
||||
## Description
|
||||
|
||||
`DataClassification` tells the platform what kind of data a table field stores so that telemetry, GDPR data-subject requests, and the platform's audit surfaces can treat it correctly. A field can declare its own value or inherit the table-level value. When neither scope supplies a valid classification, the field remains `ToBeClassified` — a placeholder meaning "not yet reviewed", not a safe default. Leaving a field that actually holds PII (an email address, a customer name, an employee code) as `ToBeClassified`, or classifying it as `SystemMetadata` ("no user or customer data"), are both under-classifications and privacy bugs, even though the code still compiles.
|
||||
`DataClassification` tells the platform what kind of data a table field stores so that telemetry, GDPR data-subject requests, and the platform's audit surfaces can treat it correctly. A field declared inside a table object can set its own value or inherit a valid table-level value; a field added by a `tableextension` has no table-level value to inherit and must always set its own. When neither scope supplies a valid classification, the field remains `ToBeClassified` — a placeholder meaning "not yet reviewed", not a safe default. Leaving a field that actually holds PII (an email address, a customer name, an employee code) as `ToBeClassified`, or classifying it as `SystemMetadata` ("no user or customer data"), are both under-classifications and privacy bugs, even though the code still compiles.
|
||||
|
||||
## Best Practice
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue