bcquality/microsoft/knowledge/security/nondebuggable-required-when-unwrapping-secrettext.md
Jesper Schulz-Wedde aca3986fd0
Correct security and privacy knowledge guidance (#92)
* Correct security and privacy guidance

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9c2eebc4-dcd5-4b85-8113-90772d818900

* Address security privacy review findings

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9c2eebc4-dcd5-4b85-8113-90772d818900

---------

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
2026-07-14 11:25:03 +02:00

1.3 KiB

bc-version domain keywords technologies countries application-area
23..
security
nondebuggable
attribute
secrettext
unwrap
debugger
al
w1
all

On-premises only: protect unavoidable SecretText.Unwrap calls

Description

SecretText.Unwrap() is supported only for Business Central on-premises and exists for compatibility. It converts a protected value to plain Text, where debugger redaction no longer applies. [NonDebuggable] prevents the debugger from inspecting a procedure's parameters and locals, but it does not make the resulting Text safe to return, log, or pass through debuggable code.

Best Practice

In SaaS, keep the value as SecretText and use secret-aware APIs instead of unwrapping. For an unavoidable on-premises legacy API that accepts only Text, keep the plain-text path as short as possible and mark every procedure in that path [NonDebuggable]. Do not return the unwrapped value. See sample: nondebuggable-required-when-unwrapping-secrettext.good.al.

Anti Pattern

Calling Unwrap() in cloud-targeted code, or calling it in an on-premises procedure that is debuggable or returns the resulting Text. Both defeat the protection that SecretText provides. See sample: nondebuggable-required-when-unwrapping-secrettext.bad.al.