bcquality/microsoft/knowledge/upgrade/guard-database-reads.md
Jesper Schulz-Wedde 2b5550c346
Some checks failed
Validate knowledge index / validate-index (push) Has been cancelled
Validate AL review fixtures / validate-review-fixtures (push) Has been cancelled
Validate frontmatter and structure / validate (push) Has been cancelled
Improve partner onboarding and documentation navigation (#174)
Lead with a complete plugin quick start and add task-oriented usage, troubleshooting, customization, and contribution guides. Preserve the broader plugin framing, correct conflicting contract guidance, support Agents folder reviews, and align repository validation. Convert existing sample references to clickable links without changing knowledge rules.

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 17:31:03 +02:00

1.3 KiB

bc-version domain keywords technologies countries application-area
all
upgrade
get
findset
findlast
guard
if-then
runtime-error
al
w1
all

Guard every database read in upgrade code with if

Description

Inside an upgrade codeunit (or any procedure transitively invoked from OnUpgradePerCompany / OnUpgradePerDatabase), an unguarded Record.Get, Record.FindSet, or Record.FindLast raises a runtime error when the row or set is missing. In upgrade context that error aborts the entire upgrade for the company or database — a far worse outcome than the missing data itself. Records the upgrade reasons about may legitimately not exist on every customer's tenant.

Best Practice

Wrap every read in an if. if Item.Get(No) then ..., if Customer.FindSet() then;, if not Vendor.FindLast() then exit;. The empty-then form if Customer.FindSet() then; is the idiomatic way to attempt a read whose only purpose is to position a record, while swallowing the "not found" case.

See sample: guard-database-reads.good.al.

Anti Pattern

Calling Item.Get(), Customer.FindSet(), or Vendor.FindLast() bare in upgrade code. The first tenant whose data does not match the upgrade's assumptions will fail to upgrade.

See sample: guard-database-reads.bad.al.