bcquality/microsoft/knowledge/security/secretstrsubstno-for-composing-secrets.md
Jesper Schulz-Wedde 2b5550c346
Some checks failed
Validate knowledge index / validate-index (push) Has been cancelled
Validate AL review fixtures / validate-review-fixtures (push) Has been cancelled
Validate frontmatter and structure / validate (push) Has been cancelled
Improve partner onboarding and documentation navigation (#174)
Lead with a complete plugin quick start and add task-oriented usage, troubleshooting, customization, and contribution guides. Preserve the broader plugin framing, correct conflicting contract guidance, support Agents folder reviews, and align repository validation. Convert existing sample references to clickable links without changing knowledge rules.

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 17:31:03 +02:00

1.3 KiB

bc-version domain keywords technologies countries application-area
23..
security
secretstrsubstno
secrettext
strsubstno
format
compose
al
w1
all

Use SecretStrSubstNo to compose strings that contain secrets

Description

SecretStrSubstNo is the secret-preserving counterpart of StrSubstNo. It inserts SecretText arguments into %1, %2, and similar placeholders and returns SecretText without materializing the result as plain text. It is the right tool for values such as a Token %1 authorization header or a URI with an API key placeholder.

Best Practice

Compose every secret-bearing string through SecretStrSubstNo, ensure the format contains a placeholder for each secret, and keep the result as SecretText. Pass it to HttpRequestMessage.SetSecretRequestUri, HttpHeaders.Add, or HttpContent.WriteFrom. See sample: secretstrsubstno-for-composing-secrets.good.al.

Anti Pattern

Keeping a credential in Text and inserting it with StrSubstNo, or calling SecretStrSubstNo with a format that has no placeholder for the secret. The first exposes the value as plain text; the second silently omits it. See sample: secretstrsubstno-for-composing-secrets.bad.al.