bcquality/microsoft/knowledge/security/commitbehavior-attribute-scopes-explicit-commits.bad.al
Kilian Seizinger 82422f94c9
Avoid Public Event publisher (#144)
* Avoid Public Event publisher

* knowledge(events): scope public-publisher detection to same-app raisers

The detection rule flagged every public event publisher, including ones
deliberately public so a sibling app can raise them - a contract `internal`
cannot express across app boundaries. Scope the finding to publishers that
are public although only their own app raises them, and record the
cross-app case as a valid Best Practice option.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0b67b90d-e4b4-4b92-9684-726c72c43b3f

---------

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0b67b90d-e4b4-4b92-9684-726c72c43b3f
2026-09-02 16:07:18 +02:00

26 lines
790 B
AL

codeunit 50151 "Sec Sample CommitBeh Bad"
{
[IntegrationEvent(true, false)]
local procedure OnBeforeApplyingDiscount(var Customer: Record Customer)
begin
end;
procedure ApplyDiscount(var Customer: Record Customer)
begin
Customer."Customer Price Group" := 'VIP';
Customer.Modify(true);
OnBeforeApplyingDiscount(Customer);
if Customer."Credit Limit (LCY)" <= 0 then
Error('Customer %1 not eligible', Customer."No.");
Commit();
end;
}
codeunit 50152 "Sec Sample CommitBeh Bad Sub"
{
[EventSubscriber(ObjectType::Codeunit, Codeunit::"Sec Sample CommitBeh Bad", 'OnBeforeApplyingDiscount', '', true, true)]
local procedure NotifyOther(var Customer: Record Customer)
begin
Commit();
end;
}