mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-08-06 17:36:53 +01:00
Ports 14 concern-sized articles (8 performance, 6 security) and 25
AL samples from BC Code Intelligence, restructured to BCQuality's v1
schema and layered under /community/knowledge/. Each article is
atomic, under 100 lines, and ships <slug>.good.al and (where the
pattern has a clear anti-example) <slug>.bad.al siblings.
Jesper's microsoft-layer leaves (al-performance-review and
al-security-review) source across every enabled layer via
*/knowledge/<domain>/**, so these additions are picked up by the
existing action skills without any new skill definitions.
Performance (8):
- use-deleteall-for-filtered-bulk-deletion
- call-setloadfields-before-filters
- load-common-fields-before-branching-on-case
- load-only-primary-key-fields-for-reference-work
- omit-filter-only-fields-from-setloadfields
- choose-maintainsiftindex-by-read-write-ratio
- avoid-growing-globals-in-singleinstance-subscribers
- order-case-branches-by-frequency
Security (6):
- classify-every-field-with-dataclassification
- protect-sensitive-data-in-temporary-tables
- guard-bulk-operations-with-istemporary
- compose-permission-sets-with-included-sets
- do-not-grant-rights-beyond-a-users-entitlement
- prefer-oauth2-over-api-keys-for-external-http-calls
Graveyard-bound items (not ported; to be captured in a later
/docs/triage-graveyard.md):
- testfield-performance (soft guidance, low actionability)
- table-event-batch-operation-impact (keep-event-subscribers-lightweight
already carries the core insight)
- Most of /roger-reviewer (AL formatting - frontier-model territory)
- sift-technology-fundamentals (descriptive, not a citable concern)
- bc-telemetry-buddy-* (tooling promotion, not guidance)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
34 lines
971 B
AL
34 lines
971 B
AL
// Building blocks: focused per-concern, marked Assignable = false so administrators
|
|
// do not accidentally assign a fragment.
|
|
permissionset 50100 "Sales Tables - Read"
|
|
{
|
|
Assignable = false;
|
|
Permissions =
|
|
tabledata Customer = R,
|
|
tabledata "Sales Header" = R,
|
|
tabledata "Sales Line" = R;
|
|
}
|
|
|
|
permissionset 50101 "Sales Tables - Edit"
|
|
{
|
|
Assignable = false;
|
|
IncludedPermissionSets = "Sales Tables - Read";
|
|
Permissions =
|
|
tabledata Customer = IM,
|
|
tabledata "Sales Header" = IMD,
|
|
tabledata "Sales Line" = IMD;
|
|
}
|
|
|
|
// Role-shaped, Assignable = true, composed from building blocks.
|
|
// Adding a new Sales table means editing one building block; both roles inherit the change.
|
|
permissionset 50110 "Sales Order Processor"
|
|
{
|
|
Assignable = true;
|
|
IncludedPermissionSets = "Sales Tables - Edit";
|
|
}
|
|
|
|
permissionset 50111 "Sales Viewer"
|
|
{
|
|
Assignable = true;
|
|
IncludedPermissionSets = "Sales Tables - Read";
|
|
}
|