bcquality/microsoft/knowledge/ui/control-addin-package-resource-ajax-needs-withcredentials.md
Jesper Schulz-Wedde b6da405376 Improve partner onboarding and documentation navigation
Lead with a complete plugin quick start and add task-oriented usage, troubleshooting, customization, and contribution guides. Preserve the broader plugin framing, correct conflicting contract guidance, support Agents folder reviews, and align repository validation. Convert existing sample references to clickable links without changing knowledge rules.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 17:25:29 +02:00

1.6 KiB

bc-version domain keywords technologies countries application-area
all
ui
control-add-in
packaged-resource
ajax
withcredentials
xhrfields
jquery
javascript
w1
all

Load packaged control add-in resources with credentialed AJAX

Description

JavaScript in a Business Central control add-in can load a static resource from its extension package with AJAX, but the request needs the Business Central context and cookies. Set xhrFields.withCredentials = true; shorthand calls such as $.get omit that setting and can work during development yet fail in production.

Best Practice

Use an AJAX form that explicitly enables withCredentials whenever a control add-in requests a packaged static resource. Keep this rule scoped to resources served from the add-in package; it is not generic advice to attach credentials to arbitrary external requests.

See sample: control-addin-package-resource-ajax-needs-withcredentials.good.js.

Anti Pattern

Using $.get(url) or an XMLHttpRequest without withCredentials = true to retrieve package content. The request can lack the context and cookies required by the Business Central service.

See sample: control-addin-package-resource-ajax-needs-withcredentials.bad.js.

Source

Control add-in object: Loading static resources using AJAX requests.