bcquality/microsoft/knowledge/security/integrationevent-must-not-expose-secrets.md
Jesper Schulz-Wedde b6da405376 Improve partner onboarding and documentation navigation
Lead with a complete plugin quick start and add task-oriented usage, troubleshooting, customization, and contribution guides. Preserve the broader plugin framing, correct conflicting contract guidance, support Agents folder reviews, and align repository validation. Convert existing sample references to clickable links without changing knowledge rules.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 17:25:29 +02:00

1.9 KiB

bc-version domain keywords technologies countries application-area
all
security
integrationevent
eventsubscriber
secrets
credentials
publisher
al
w1
all

Do not pass credentials or secrets through IntegrationEvent parameters

Description

[IntegrationEvent] publishes a hook that any extension can subscribe to. Every parameter of the event signature is visible to every subscriber — including var parameters, which subscribers can both read and modify. A publisher that includes an API key, password, bearer token, or other secret in the event signature hands that secret to every subscriber on the tenant, including subscribers in extensions the publisher has no relationship with. There is no permission or partner-only filter that limits who may subscribe.

Best Practice

Restrict event payloads to the non-sensitive context a subscriber legitimately needs: the business record being processed (a Customer), the operation being performed, an IsHandled flag that lets a subscriber skip the default behaviour, and a mutable payload object whose contents the publisher controls. Authentication is handled by the publisher before or after the event, never inside the parameters. See sample: integrationevent-must-not-expose-secrets.good.al.

Anti Pattern

[IntegrationEvent(false, false)] procedure OnBeforeSendRequest(var ApiKey: Text; var Password: Text; var RequestUrl: Text) — any extension on the tenant can subscribe, read ApiKey and Password, and persist them elsewhere. Reviewers should flag any event parameter whose name or type suggests a secret (ApiKey, Token, Password, Secret, Credential, SecretText — even SecretText should not flow through an event surface). See sample: integrationevent-must-not-expose-secrets.bad.al.