bcquality/microsoft/knowledge/breaking-changes/do-not-expose-sensitive-data-through-public-api.good.al
Jesper Schulz-Wedde 5706959e4a
Fix lifecycle compatibility guidance (#93)
* Fix lifecycle compatibility guidance

Correct high-confidence Business Central guidance and samples for upgrade tags, collectible errors, trigger semantics, obsoletion, events, interfaces, API contracts, and test transactions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e05a43e7-6448-4d67-9c73-798523f5d945

* Address guidance review findings

Gate SecretText guidance to BC23 and clarify that the collectible-error sample intentionally emits a message-only blocking aggregate.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e05a43e7-6448-4d67-9c73-798523f5d945

---------

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
2026-07-14 11:26:16 +02:00

25 lines
648 B
AL

codeunit 50320 "Payment Client Good"
{
var
AccessToken: SecretText;
// Credential remains SecretText as it flows inward and is stored.
internal procedure SetAccessToken(NewToken: SecretText)
begin
AccessToken := NewToken;
end;
// Public API exposes only non-sensitive data — a masked reference, never the token.
procedure GetMaskedReference(): Text
var
Reference: Text;
begin
Reference := LastReference();
exit('****-' + CopyStr(Reference, StrLen(Reference) - 3));
end;
local procedure LastReference(): Text
begin
exit('REF000123456');
end;
}