bcquality/microsoft/knowledge/security/do-not-expose-sensitive-data-in-event-publishers.md
Jesper Schulz-Wedde 5bcdc55df9 Sync knowledge articles with review agent instructions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-05 14:08:32 +02:00

1.5 KiB

bc-version domain keywords technologies countries application-area
all
security
event
publisher
extensibility
var-parameter
al
w1
all

Do not expose sensitive data in event publishers

Contributions welcome — open a PR to refine or extend this article.

Description

Events in AL are extensibility contracts. Every subscriber — third-party, internal, or installed after the fact — receives the full set of event parameters. Parameters that carry secrets, pre-authorization state, or variables the publisher relies on for access control effectively become public, and var-parameters can be mutated by a subscriber to alter publisher behaviour.

Best Practice

Design event signatures to carry only the data a subscriber legitimately needs. Do not pass SecretText, credential material, or flags the publisher depends on for access control. Guard variables such as HasAccess, SkipValidation, or CanExport must not be var parameters on an OnBefore event; notify subscribers after the internal check with value parameters they cannot mutate.

See sample: do-not-expose-sensitive-data-in-event-publishers.good.al.

Anti Pattern

An OnBeforeElevateAccess publisher that exposes var CanAccess: Boolean or var SkipValidation: Boolean — any subscriber installed on the tenant can flip it to true and bypass the check. Or a publisher that passes a SecretText parameter it obtained internally, handing it to every subscriber.

See sample: do-not-expose-sensitive-data-in-event-publishers.bad.al.