* Add P0 integration and control add-in guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 02baffe8-0600-430d-81fa-a9993685e7cb * Correct API part multiplicity guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 02baffe8-0600-430d-81fa-a9993685e7cb * Refine API part multiplicity guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1c37924e-9749-4e63-9d58-bd73d659f736 --------- Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
1.5 KiB
| bc-version | domain | keywords | technologies | countries | application-area | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
ui |
|
|
|
|
Load packaged control add-in resources with credentialed AJAX
Description
JavaScript in a Business Central control add-in can load a static resource from its extension package with AJAX, but the request needs the Business Central context and cookies. Set xhrFields.withCredentials = true; shorthand calls such as $.get omit that setting and can work during development yet fail in production.
Best Practice
Use an AJAX form that explicitly enables withCredentials whenever a control add-in requests a packaged static resource. Keep this rule scoped to resources served from the add-in package; it is not generic advice to attach credentials to arbitrary external requests.
See sample: control-addin-package-resource-ajax-needs-withcredentials.good.js.
Anti Pattern
Using $.get(url) or an XMLHttpRequest without withCredentials = true to retrieve package content. The request can lack the context and cookies required by the Business Central service.
See sample: control-addin-package-resource-ajax-needs-withcredentials.bad.js.
Source
Control add-in object: Loading static resources using AJAX requests.