bcquality/microsoft/knowledge/security/prefer-oauth2-over-api-keys-for-external-http-calls.bad.al
Jesper Schulz-Wedde 347984ac74 Promote security knowledge from community to Microsoft layer
Pure git-mv relocation of the SECURITY domain from the community layer to the Microsoft layer. No content changes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-25 14:03:22 +02:00

29 lines
960 B
AL

codeunit 50100 "Partner API Client"
{
procedure FetchOrders(var Response: Text): Boolean
var
HttpClient: HttpClient;
HttpRequest: HttpRequestMessage;
HttpResponse: HttpResponseMessage;
ApiKey: Text;
begin
// API key stored as plain Text in a setup table - not IsolatedStorage,
// not SecretText. Rotation means the admin editing a Text field;
// a single disclosure exposes every tenant running this extension.
ApiKey := GetApiKeyFromSetupTable();
HttpRequest.SetRequestUri('https://partner.example.com/orders');
HttpRequest.Method('GET');
HttpRequest.GetHeaders().Add('X-API-Key', ApiKey);
if not HttpClient.Send(HttpRequest, HttpResponse) then
exit(false);
HttpResponse.Content.ReadAs(Response);
exit(HttpResponse.IsSuccessStatusCode);
end;
local procedure GetApiKeyFromSetupTable(): Text
begin
end;
}