bcquality/microsoft/knowledge/security
Michael Dieringer 67962727f6 Fix ten focused correctness items plus sample links from Jesper's 2026-09-15 re-review
Six carried-over threads:
- api-page-least-privilege-write-access fixtures: added the mandatory
  EntityName/EntitySetName properties (AL0485).
- pages-must-not-contain-business-logic fixtures: Sales Line has no
  "Total Amount" field; replaced with the real "Line Amount" (field 103).
- test-feature-scenario-tags.good.al and test-one-when-per-test.good.al:
  CreatePriceHeader leaves a price list in Draft status, which price
  calculation ignores. Added Validate(Status, Active) + Modify before the
  sales line that depends on it. Verified Status field/enum against
  PriceListHeader.Table.al and PriceStatus.Enum.al in the BCApps clone.
- exposed-objects-must-be-in-a-permission-set.md: a published codeunit is
  a SOAP endpoint (SOAP is deprecated), not OData - Page/Query are the
  OData object types. Corrected and pointed new integrations at API
  pages/queries instead.
- al-error-handling-review.md: the log-writes-must-survive-rollback cue
  selected on Session.StartSession, which only appears in the compliant
  fix, never in the anti-pattern - the bad fixture could never be
  worklisted. Recued on the actual risk shape (log insert around a
  failed TryFunction/GetLastError* path, then raise/propagate), with
  StartSession as an explicit compliant discriminator instead.
- page-design-must-match-bc-page-type-conventions.md: the enum value is
  NavigatePage, not Navigate; noted the type list is a selected subset,
  not an exhaustive PageType catalogue (PromptDialog, ConfigurationDialog,
  UserControlHost, XmlPort also exist, out of this article's scope).

Four new correctness gaps:
- release-must-update-app-version.md: "the version is the only identity"
  was backwards - id is the app's stable identity, version identifies a
  release/code-state of it.
- defensive-vs-offensive-code-must-match-blast-radius.good.al: the "low
  blast radius" example had no else branch, so a failed Customer.Get()
  left the field at its prior/default value instead of the explicit
  chosen fallback the article claims to demonstrate. Added the else.
- bcpt-scenarios-must-be-app-specific.good.al: InitTest and both measured
  StartScenario/EndScenario sections were empty/comment-only, so the
  "app-specific" fixture measured no actual work. Filled in a real,
  self-contained header+line creation path.
- upgrade-tag-logic-must-not-nest-deeply.good.al: the flattened version
  dropped both safety conditions the bad fixture had (Discount % = 0,
  nonblank posting group), silently changing behavior instead of just
  removing nesting. Extracted the guarded update into a helper with both
  conditions preserved as early exits.

Also converted this PR's remaining plain-backtick "See sample:" sample
references (16 articles) to the READ-convention markdown-link form,
matching the fix already made on #156/#158.

Rebased onto upstream/main (conflicts in al-ui-review.md, al-style-review.md,
al-upgrade-review.md against merged upstream PRs - all additive, both
sides' worklist cues retained).
2026-09-21 22:44:17 +02:00
..
al-has-no-built-in-htmlencode.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
al-has-no-built-in-htmlencode.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
al-has-no-built-in-htmlencode.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
commitbehavior-attribute-scopes-explicit-commits.bad.al Avoid Public Event publisher (#144) 2026-09-02 16:07:18 +02:00
commitbehavior-attribute-scopes-explicit-commits.good.al Avoid Public Event publisher (#144) 2026-09-02 16:07:18 +02:00
commitbehavior-attribute-scopes-explicit-commits.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
compose-permission-sets-with-included-sets.bad.al Promote security knowledge from community to Microsoft layer (#49) 2026-07-14 11:23:57 +02:00
compose-permission-sets-with-included-sets.good.al Promote security knowledge from community to Microsoft layer (#49) 2026-07-14 11:23:57 +02:00
compose-permission-sets-with-included-sets.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
do-not-grant-rights-beyond-a-users-entitlement.md Promote security knowledge from community to Microsoft layer (#49) 2026-07-14 11:23:57 +02:00
exposed-objects-must-be-in-a-permission-set.bad.al Add 18 more community AL/BC patterns across appsource, data-modeling, error-handling, security, style, testing, ui, upgrade, and web-services 2026-09-21 22:42:49 +02:00
exposed-objects-must-be-in-a-permission-set.good.al Add 18 more community AL/BC patterns across appsource, data-modeling, error-handling, security, style, testing, ui, upgrade, and web-services 2026-09-21 22:42:49 +02:00
exposed-objects-must-be-in-a-permission-set.md Fix ten focused correctness items plus sample links from Jesper's 2026-09-15 re-review 2026-09-21 22:44:17 +02:00
getlasterrortext-storage-is-privacy-not-security.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
getlasterrortext-storage-is-privacy-not-security.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
guard-bulk-operations-with-istemporary.bad.al Promote knowledge for Microsoft review skills (#153) 2026-09-03 15:06:01 +02:00
guard-bulk-operations-with-istemporary.good.al Promote knowledge for Microsoft review skills (#153) 2026-09-03 15:06:01 +02:00
guard-bulk-operations-with-istemporary.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
indirect-permissions-for-elevated-access.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
indirect-permissions-for-elevated-access.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
indirect-permissions-for-elevated-access.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
inherent-permissions-minimal-grant.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
inherent-permissions-minimal-grant.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
inherent-permissions-minimal-grant.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
integrationevent-must-not-expose-secrets.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
integrationevent-must-not-expose-secrets.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
integrationevent-must-not-expose-secrets.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
integrationevent-var-parameter-bypasses-security-guards.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
integrationevent-var-parameter-bypasses-security-guards.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
integrationevent-var-parameter-bypasses-security-guards.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
internal-access-is-not-a-security-boundary.bad.al Complete AL review knowledge readiness (#108) 2026-07-15 10:55:25 +02:00
internal-access-is-not-a-security-boundary.good.al Complete AL review knowledge readiness (#108) 2026-07-15 10:55:25 +02:00
internal-access-is-not-a-security-boundary.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
isolatedstorage-access-must-be-local-or-internal.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
isolatedstorage-access-must-be-local-or-internal.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
isolatedstorage-access-must-be-local-or-internal.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
isolatedstorage-datascope-module-vs-company.bad.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
isolatedstorage-datascope-module-vs-company.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
isolatedstorage-datascope-module-vs-company.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
isolatedstorage-setencrypted-for-sensitive-values.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
isolatedstorage-setencrypted-for-sensitive-values.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
isolatedstorage-setencrypted-for-sensitive-values.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
nondebuggable-required-when-unwrapping-secrettext.bad.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
nondebuggable-required-when-unwrapping-secrettext.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
nondebuggable-required-when-unwrapping-secrettext.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
permission-set-avoid-wildcard-grants.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
permission-set-avoid-wildcard-grants.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
permission-set-avoid-wildcard-grants.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
prefer-oauth2-over-api-keys-for-external-http-calls.bad.al Promote security knowledge from community to Microsoft layer (#49) 2026-07-14 11:23:57 +02:00
prefer-oauth2-over-api-keys-for-external-http-calls.good.al Promote security knowledge from community to Microsoft layer (#49) 2026-07-14 11:23:57 +02:00
prefer-oauth2-over-api-keys-for-external-http-calls.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
protect-sensitive-data-in-temporary-tables.bad.al Promote security knowledge from community to Microsoft layer (#49) 2026-07-14 11:23:57 +02:00
protect-sensitive-data-in-temporary-tables.good.al Promote security knowledge from community to Microsoft layer (#49) 2026-07-14 11:23:57 +02:00
protect-sensitive-data-in-temporary-tables.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
recordref-open-with-caller-table-must-not-be-public.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
recordref-open-with-caller-table-must-not-be-public.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
recordref-open-with-caller-table-must-not-be-public.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
secrets-isolated-storage.bad.al Promote validated community knowledge (#105) 2026-07-14 14:20:27 +02:00
secrets-isolated-storage.good.al Promote validated community knowledge (#105) 2026-07-14 14:20:27 +02:00
secrets-isolated-storage.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
secretstrsubstno-for-composing-secrets.bad.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
secretstrsubstno-for-composing-secrets.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
secretstrsubstno-for-composing-secrets.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
secrettext-for-credentials.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
secrettext-for-credentials.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
secrettext-for-credentials.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
secrettext-with-httpclient.bad.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
secrettext-with-httpclient.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
secrettext-with-httpclient.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
validate-unauthenticated-response-before-use.bad.al Add security knowledge: validate unauthenticated endpoint responses 2026-09-15 13:16:53 +02:00
validate-unauthenticated-response-before-use.good.al Add security knowledge: validate unauthenticated endpoint responses 2026-09-15 13:16:53 +02:00
validate-unauthenticated-response-before-use.md Link samples using the READ markdown-link convention 2026-09-15 13:48:59 +02:00
validate-user-configurable-urls.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
validate-user-configurable-urls.good.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
validate-user-configurable-urls.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
validatetablerelation-false-on-user-input.bad.al Regenerate microsoft/knowledge from upstream BCApps instructions 2026-05-21 09:53:09 +02:00
validatetablerelation-false-on-user-input.good.al Correct security and privacy knowledge guidance (#92) 2026-07-14 11:25:03 +02:00
validatetablerelation-false-on-user-input.md Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00