mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 14:46:55 +01:00
Six carried-over threads: - api-page-least-privilege-write-access fixtures: added the mandatory EntityName/EntitySetName properties (AL0485). - pages-must-not-contain-business-logic fixtures: Sales Line has no "Total Amount" field; replaced with the real "Line Amount" (field 103). - test-feature-scenario-tags.good.al and test-one-when-per-test.good.al: CreatePriceHeader leaves a price list in Draft status, which price calculation ignores. Added Validate(Status, Active) + Modify before the sales line that depends on it. Verified Status field/enum against PriceListHeader.Table.al and PriceStatus.Enum.al in the BCApps clone. - exposed-objects-must-be-in-a-permission-set.md: a published codeunit is a SOAP endpoint (SOAP is deprecated), not OData - Page/Query are the OData object types. Corrected and pointed new integrations at API pages/queries instead. - al-error-handling-review.md: the log-writes-must-survive-rollback cue selected on Session.StartSession, which only appears in the compliant fix, never in the anti-pattern - the bad fixture could never be worklisted. Recued on the actual risk shape (log insert around a failed TryFunction/GetLastError* path, then raise/propagate), with StartSession as an explicit compliant discriminator instead. - page-design-must-match-bc-page-type-conventions.md: the enum value is NavigatePage, not Navigate; noted the type list is a selected subset, not an exhaustive PageType catalogue (PromptDialog, ConfigurationDialog, UserControlHost, XmlPort also exist, out of this article's scope). Four new correctness gaps: - release-must-update-app-version.md: "the version is the only identity" was backwards - id is the app's stable identity, version identifies a release/code-state of it. - defensive-vs-offensive-code-must-match-blast-radius.good.al: the "low blast radius" example had no else branch, so a failed Customer.Get() left the field at its prior/default value instead of the explicit chosen fallback the article claims to demonstrate. Added the else. - bcpt-scenarios-must-be-app-specific.good.al: InitTest and both measured StartScenario/EndScenario sections were empty/comment-only, so the "app-specific" fixture measured no actual work. Filled in a real, self-contained header+line creation path. - upgrade-tag-logic-must-not-nest-deeply.good.al: the flattened version dropped both safety conditions the bad fixture had (Discount % = 0, nonblank posting group), silently changing behavior instead of just removing nesting. Extracted the guarded update into a helper with both conditions preserved as early exits. Also converted this PR's remaining plain-backtick "See sample:" sample references (16 articles) to the READ-convention markdown-link form, matching the fix already made on #156/#158. Rebased onto upstream/main (conflicts in al-ui-review.md, al-style-review.md, al-upgrade-review.md against merged upstream PRs - all additive, both sides' worklist cues retained). |
||
|---|---|---|
| .. | ||
| al-has-no-built-in-htmlencode.bad.al | ||
| al-has-no-built-in-htmlencode.good.al | ||
| al-has-no-built-in-htmlencode.md | ||
| commitbehavior-attribute-scopes-explicit-commits.bad.al | ||
| commitbehavior-attribute-scopes-explicit-commits.good.al | ||
| commitbehavior-attribute-scopes-explicit-commits.md | ||
| compose-permission-sets-with-included-sets.bad.al | ||
| compose-permission-sets-with-included-sets.good.al | ||
| compose-permission-sets-with-included-sets.md | ||
| do-not-grant-rights-beyond-a-users-entitlement.md | ||
| exposed-objects-must-be-in-a-permission-set.bad.al | ||
| exposed-objects-must-be-in-a-permission-set.good.al | ||
| exposed-objects-must-be-in-a-permission-set.md | ||
| getlasterrortext-storage-is-privacy-not-security.bad.al | ||
| getlasterrortext-storage-is-privacy-not-security.md | ||
| guard-bulk-operations-with-istemporary.bad.al | ||
| guard-bulk-operations-with-istemporary.good.al | ||
| guard-bulk-operations-with-istemporary.md | ||
| indirect-permissions-for-elevated-access.bad.al | ||
| indirect-permissions-for-elevated-access.good.al | ||
| indirect-permissions-for-elevated-access.md | ||
| inherent-permissions-minimal-grant.bad.al | ||
| inherent-permissions-minimal-grant.good.al | ||
| inherent-permissions-minimal-grant.md | ||
| integrationevent-must-not-expose-secrets.bad.al | ||
| integrationevent-must-not-expose-secrets.good.al | ||
| integrationevent-must-not-expose-secrets.md | ||
| integrationevent-var-parameter-bypasses-security-guards.bad.al | ||
| integrationevent-var-parameter-bypasses-security-guards.good.al | ||
| integrationevent-var-parameter-bypasses-security-guards.md | ||
| internal-access-is-not-a-security-boundary.bad.al | ||
| internal-access-is-not-a-security-boundary.good.al | ||
| internal-access-is-not-a-security-boundary.md | ||
| isolatedstorage-access-must-be-local-or-internal.bad.al | ||
| isolatedstorage-access-must-be-local-or-internal.good.al | ||
| isolatedstorage-access-must-be-local-or-internal.md | ||
| isolatedstorage-datascope-module-vs-company.bad.al | ||
| isolatedstorage-datascope-module-vs-company.good.al | ||
| isolatedstorage-datascope-module-vs-company.md | ||
| isolatedstorage-setencrypted-for-sensitive-values.bad.al | ||
| isolatedstorage-setencrypted-for-sensitive-values.good.al | ||
| isolatedstorage-setencrypted-for-sensitive-values.md | ||
| nondebuggable-required-when-unwrapping-secrettext.bad.al | ||
| nondebuggable-required-when-unwrapping-secrettext.good.al | ||
| nondebuggable-required-when-unwrapping-secrettext.md | ||
| permission-set-avoid-wildcard-grants.bad.al | ||
| permission-set-avoid-wildcard-grants.good.al | ||
| permission-set-avoid-wildcard-grants.md | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.bad.al | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.good.al | ||
| prefer-oauth2-over-api-keys-for-external-http-calls.md | ||
| protect-sensitive-data-in-temporary-tables.bad.al | ||
| protect-sensitive-data-in-temporary-tables.good.al | ||
| protect-sensitive-data-in-temporary-tables.md | ||
| recordref-open-with-caller-table-must-not-be-public.bad.al | ||
| recordref-open-with-caller-table-must-not-be-public.good.al | ||
| recordref-open-with-caller-table-must-not-be-public.md | ||
| secrets-isolated-storage.bad.al | ||
| secrets-isolated-storage.good.al | ||
| secrets-isolated-storage.md | ||
| secretstrsubstno-for-composing-secrets.bad.al | ||
| secretstrsubstno-for-composing-secrets.good.al | ||
| secretstrsubstno-for-composing-secrets.md | ||
| secrettext-for-credentials.bad.al | ||
| secrettext-for-credentials.good.al | ||
| secrettext-for-credentials.md | ||
| secrettext-with-httpclient.bad.al | ||
| secrettext-with-httpclient.good.al | ||
| secrettext-with-httpclient.md | ||
| validate-unauthenticated-response-before-use.bad.al | ||
| validate-unauthenticated-response-before-use.good.al | ||
| validate-unauthenticated-response-before-use.md | ||
| validate-user-configurable-urls.bad.al | ||
| validate-user-configurable-urls.good.al | ||
| validate-user-configurable-urls.md | ||
| validatetablerelation-false-on-user-input.bad.al | ||
| validatetablerelation-false-on-user-input.good.al | ||
| validatetablerelation-false-on-user-input.md | ||