mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 14:46:55 +01:00
- log-writes-must-survive-rollback.good.al: fixed invalid trigger OnRun(var Rec: ...) declaration; Rec is implicit when TableNo is set. - exposed-objects-must-be-in-a-permission-set.md: distinguished the three exposure mechanisms (page/query web service or API, codeunit published as a web service, [ServiceEnabled] bound action on a page) and their actual permission targets (page/query "..." = X vs codeunit "..." = X). - code-must-not-change-workdate.md: scoped from an absolute "never" to "not as a side effect of unrelated logic" - verified real WorkDate(x) setter usage in BCApps demo-data generators and test codeunits. - bcpt-scenarios-must-be-app-specific.md: SingleInstance and StartScenario/EndScenario reframed as context-dependent patterns, not mandatory requirements - BCPT Create Customer uses neither. - test-feature-scenario-tags.good.al/.bad.al: replaced the invented LibrarySales.CreateCustomerWithPrice/"Item Price Mgt." calls with a real, verified price-list-line test using Library - Sales/Library - Inventory/ Library - Price Calculation. - page-design-must-match-bc-page-type-conventions.md: scoped the missing UsageCategory anti-pattern to pages intended as searchable entry points. - defensive-vs-offensive-code-must-match-blast-radius.md/.good.al/.bad.al: replaced the VAT registration number "low blast radius" example with a genuinely cosmetic field (customer home page URL). - source-organized-by-feature-not-object-type.md: anti-pattern reframed as inconsistency with a repo's own convention, not the object-type scheme itself. - pictures-must-use-media-not-blob.md: removed leftover "image variants" wording contradicting the already-corrected MediaSet description. Proactively fixed while sweeping all fixtures for invented APIs: - given-blocks-must-cover-full-precondition-chain.bad.al: PostSalesOrder called with wrong arity and referenced an undeclared variable. - ui-test-codeunit-naming.good.al/.bad.al: replaced the same fake "Item Price Mgt."/TestPage "Item Price" with real Library - Sales calls and the real Customer Card TestPage. Worklist completeness: added review-skill cues for the 12 of 18 new rules that had none (al-appsource-review.md, al-data-modeling-review.md, al-error-handling-review.md, al-security-review.md, al-style-review.md x3, al-testing-review.md x2, al-ui-review.md, al-upgrade-review.md, al-web-services-review.md), and fixed test-feature-scenario-tags' cue, which only matched the compliant (tagged) shape instead of the anti-pattern (untagged/generic-named test). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| al-has-no-built-in-htmlencode.bad.al | ||
| al-has-no-built-in-htmlencode.good.al | ||
| al-has-no-built-in-htmlencode.md | ||
| commitbehavior-attribute-scopes-explicit-commits.bad.al | ||
| commitbehavior-attribute-scopes-explicit-commits.good.al | ||
| commitbehavior-attribute-scopes-explicit-commits.md | ||
| compose-permission-sets-with-included-sets.bad.al | ||
| compose-permission-sets-with-included-sets.good.al | ||
| compose-permission-sets-with-included-sets.md | ||
| do-not-grant-rights-beyond-a-users-entitlement.md | ||
| exposed-objects-must-be-in-a-permission-set.bad.al | ||
| exposed-objects-must-be-in-a-permission-set.good.al | ||
| exposed-objects-must-be-in-a-permission-set.md | ||
| getlasterrortext-storage-is-privacy-not-security.bad.al | ||
| getlasterrortext-storage-is-privacy-not-security.md | ||
| guard-bulk-operations-with-istemporary.bad.al | ||
| guard-bulk-operations-with-istemporary.good.al | ||
| guard-bulk-operations-with-istemporary.md | ||
| indirect-permissions-for-elevated-access.bad.al | ||
| indirect-permissions-for-elevated-access.good.al | ||
| indirect-permissions-for-elevated-access.md | ||
| inherent-permissions-minimal-grant.bad.al | ||
| inherent-permissions-minimal-grant.good.al | ||
| inherent-permissions-minimal-grant.md | ||
| integrationevent-must-not-expose-secrets.bad.al | ||
| integrationevent-must-not-expose-secrets.good.al | ||
| integrationevent-must-not-expose-secrets.md | ||
| integrationevent-var-parameter-bypasses-security-guards.bad.al | ||
| integrationevent-var-parameter-bypasses-security-guards.good.al | ||
| integrationevent-var-parameter-bypasses-security-guards.md | ||
| internal-access-is-not-a-security-boundary.bad.al | ||
| internal-access-is-not-a-security-boundary.good.al | ||
| internal-access-is-not-a-security-boundary.md | ||
| isolatedstorage-access-must-be-local-or-internal.bad.al | ||
| isolatedstorage-access-must-be-local-or-internal.good.al | ||
| isolatedstorage-access-must-be-local-or-internal.md | ||
| isolatedstorage-datascope-module-vs-company.bad.al | ||
| isolatedstorage-datascope-module-vs-company.good.al | ||
| isolatedstorage-datascope-module-vs-company.md | ||
| isolatedstorage-setencrypted-for-sensitive-values.bad.al | ||
| isolatedstorage-setencrypted-for-sensitive-values.good.al | ||
| isolatedstorage-setencrypted-for-sensitive-values.md | ||
| nondebuggable-required-when-unwrapping-secrettext.bad.al | ||
| nondebuggable-required-when-unwrapping-secrettext.good.al | ||
| nondebuggable-required-when-unwrapping-secrettext.md | ||
| permission-set-avoid-wildcard-grants.bad.al | ||
| permission-set-avoid-wildcard-grants.good.al | ||
| permission-set-avoid-wildcard-grants.md | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.bad.al | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.good.al | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.md | ||
| protect-sensitive-data-in-temporary-tables.bad.al | ||
| protect-sensitive-data-in-temporary-tables.good.al | ||
| protect-sensitive-data-in-temporary-tables.md | ||
| recordref-open-with-caller-table-must-not-be-public.bad.al | ||
| recordref-open-with-caller-table-must-not-be-public.good.al | ||
| recordref-open-with-caller-table-must-not-be-public.md | ||
| secrets-isolated-storage.bad.al | ||
| secrets-isolated-storage.good.al | ||
| secrets-isolated-storage.md | ||
| secretstrsubstno-for-composing-secrets.bad.al | ||
| secretstrsubstno-for-composing-secrets.good.al | ||
| secretstrsubstno-for-composing-secrets.md | ||
| secrettext-for-credentials.bad.al | ||
| secrettext-for-credentials.good.al | ||
| secrettext-for-credentials.md | ||
| secrettext-with-httpclient.bad.al | ||
| secrettext-with-httpclient.good.al | ||
| secrettext-with-httpclient.md | ||
| validate-unauthenticated-response-before-use.bad.al | ||
| validate-unauthenticated-response-before-use.good.al | ||
| validate-unauthenticated-response-before-use.md | ||
| validate-user-configurable-urls.bad.al | ||
| validate-user-configurable-urls.good.al | ||
| validate-user-configurable-urls.md | ||
| validatetablerelation-false-on-user-input.bad.al | ||
| validatetablerelation-false-on-user-input.good.al | ||
| validatetablerelation-false-on-user-input.md | ||