mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 22:56:55 +01:00
- release-must-update-app-version.md: reframe around AppSource's actual
strict full-version-ordering requirement; scope branching-policy
claims as team convention, not platform rule.
- pictures-must-use-media-not-blob.md: MediaSet is a collection of
independent media objects, not automatic image variants/thumbnails.
- log-writes-must-survive-rollback.{md,good.al}: StartSession's only
data channel into the new session is its Record parameter to a
TableNo-scoped codeunit; a setter called on a local instance before
starting the session populates nothing in the new session.
- exposed-objects-must-be-in-a-permission-set.md: correct the three
exposure mechanisms (Web Services config, PageType/QueryType=API,
ServiceEnabled as a method-only attribute).
- pages-must-not-contain-business-logic.md: scope to persisted
mutations and cross-entry-point rules; presentation-only
calculations and table-owned invariants are not violations.
- given-blocks-must-cover-full-precondition-chain.good.al: replace
invented LibrarySales calls with the real API
(CreateCustomer/CreateSalesOrderForCustomerNo/PostSalesDocument).
- test-feature-scenario-tags.{md,good.al}: move [SCENARIO] inside the
test procedure body to match the current BCApps corpus; keep
[FEATURE] at codeunit level per Microsoft's own documented option.
- ui-test-codeunit-naming.md: scope the _UT suffix and adjacent-ID
pairing as an explicit team convention, not a BCApps-wide standard.
- page-design-must-match-bc-page-type-conventions.md /
table-design-must-match-bc-table-type-conventions.md: Card's
single-key primary-key claim is a contextual heuristic, not a
mandatory constraint (Ship-to Address, Customer/Vendor Bank Account
are real composite-key Card pages); a Subsidiary table with its own
identity commonly gets List+Card, not Worksheet/Tabular.
- api-page-least-privilege-write-access.{md,good.al}: only page-placed
fields are ever exposed; set InsertAllowed/DeleteAllowed=false in the
good sample so a narrow field set can't still create/delete records.
- source-organized-by-feature-not-object-type.md,
test-one-when-per-test.md: scope as team/testing-design conventions,
not Microsoft platform requirements.
- upgrade-tag-logic-must-not-nest-deeply.md: add the Microsoft Learn
citation that already backs the two-level nesting limit.
- Wire the new articles into the testing/data-modeling/error-handling/
security/ui review skills' candidate-selection signals.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| al-has-no-built-in-htmlencode.bad.al | ||
| al-has-no-built-in-htmlencode.good.al | ||
| al-has-no-built-in-htmlencode.md | ||
| commitbehavior-attribute-scopes-explicit-commits.bad.al | ||
| commitbehavior-attribute-scopes-explicit-commits.good.al | ||
| commitbehavior-attribute-scopes-explicit-commits.md | ||
| compose-permission-sets-with-included-sets.bad.al | ||
| compose-permission-sets-with-included-sets.good.al | ||
| compose-permission-sets-with-included-sets.md | ||
| do-not-grant-rights-beyond-a-users-entitlement.md | ||
| exposed-objects-must-be-in-a-permission-set.bad.al | ||
| exposed-objects-must-be-in-a-permission-set.good.al | ||
| exposed-objects-must-be-in-a-permission-set.md | ||
| getlasterrortext-storage-is-privacy-not-security.bad.al | ||
| getlasterrortext-storage-is-privacy-not-security.md | ||
| guard-bulk-operations-with-istemporary.bad.al | ||
| guard-bulk-operations-with-istemporary.good.al | ||
| guard-bulk-operations-with-istemporary.md | ||
| indirect-permissions-for-elevated-access.bad.al | ||
| indirect-permissions-for-elevated-access.good.al | ||
| indirect-permissions-for-elevated-access.md | ||
| inherent-permissions-minimal-grant.bad.al | ||
| inherent-permissions-minimal-grant.good.al | ||
| inherent-permissions-minimal-grant.md | ||
| integrationevent-must-not-expose-secrets.bad.al | ||
| integrationevent-must-not-expose-secrets.good.al | ||
| integrationevent-must-not-expose-secrets.md | ||
| integrationevent-var-parameter-bypasses-security-guards.bad.al | ||
| integrationevent-var-parameter-bypasses-security-guards.good.al | ||
| integrationevent-var-parameter-bypasses-security-guards.md | ||
| internal-access-is-not-a-security-boundary.bad.al | ||
| internal-access-is-not-a-security-boundary.good.al | ||
| internal-access-is-not-a-security-boundary.md | ||
| isolatedstorage-access-must-be-local-or-internal.bad.al | ||
| isolatedstorage-access-must-be-local-or-internal.good.al | ||
| isolatedstorage-access-must-be-local-or-internal.md | ||
| isolatedstorage-datascope-module-vs-company.bad.al | ||
| isolatedstorage-datascope-module-vs-company.good.al | ||
| isolatedstorage-datascope-module-vs-company.md | ||
| isolatedstorage-setencrypted-for-sensitive-values.bad.al | ||
| isolatedstorage-setencrypted-for-sensitive-values.good.al | ||
| isolatedstorage-setencrypted-for-sensitive-values.md | ||
| nondebuggable-required-when-unwrapping-secrettext.bad.al | ||
| nondebuggable-required-when-unwrapping-secrettext.good.al | ||
| nondebuggable-required-when-unwrapping-secrettext.md | ||
| permission-set-avoid-wildcard-grants.bad.al | ||
| permission-set-avoid-wildcard-grants.good.al | ||
| permission-set-avoid-wildcard-grants.md | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.bad.al | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.good.al | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.md | ||
| protect-sensitive-data-in-temporary-tables.bad.al | ||
| protect-sensitive-data-in-temporary-tables.good.al | ||
| protect-sensitive-data-in-temporary-tables.md | ||
| recordref-open-with-caller-table-must-not-be-public.bad.al | ||
| recordref-open-with-caller-table-must-not-be-public.good.al | ||
| recordref-open-with-caller-table-must-not-be-public.md | ||
| secrets-isolated-storage.bad.al | ||
| secrets-isolated-storage.good.al | ||
| secrets-isolated-storage.md | ||
| secretstrsubstno-for-composing-secrets.bad.al | ||
| secretstrsubstno-for-composing-secrets.good.al | ||
| secretstrsubstno-for-composing-secrets.md | ||
| secrettext-for-credentials.bad.al | ||
| secrettext-for-credentials.good.al | ||
| secrettext-for-credentials.md | ||
| secrettext-with-httpclient.bad.al | ||
| secrettext-with-httpclient.good.al | ||
| secrettext-with-httpclient.md | ||
| validate-unauthenticated-response-before-use.bad.al | ||
| validate-unauthenticated-response-before-use.good.al | ||
| validate-unauthenticated-response-before-use.md | ||
| validate-user-configurable-urls.bad.al | ||
| validate-user-configurable-urls.good.al | ||
| validate-user-configurable-urls.md | ||
| validatetablerelation-false-on-user-input.bad.al | ||
| validatetablerelation-false-on-user-input.good.al | ||
| validatetablerelation-false-on-user-input.md | ||