mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-08-06 09:26:52 +01:00
* Promote security knowledge from community to Microsoft layer Pure git-mv relocation of the SECURITY domain from the community layer to the Microsoft layer. No content changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address review feedback on security knowledge promotion - do-not-grant-rights-beyond-a-users-entitlement.md: drop the See sample reference to a .good.al file that does not exist - Remove the 'Contributions welcome' boilerplate line from compose-permission-sets, prefer-oauth2, and protect-sensitive-data - protect-sensitive-data-in-temporary-tables: remove the pointless DeleteAll on the locally scoped temp buffer in the good sample and reword Best Practice to note local buffers are cleaned up automatically - Drop guard-bulk-operations-with-istemporary from the promotion; it stays in the community layer pending a decision on whether it is security Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Remove Contributions welcome boilerplate from do-not-grant article for consistency Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
21 lines
617 B
AL
21 lines
617 B
AL
// Two role-shaped sets, each re-enumerating the same objects. Adding a new
|
|
// Sales table means editing both sets by hand; forgetting one creates a
|
|
// subtle authorization bug where one role was updated and its sibling was not.
|
|
|
|
permissionset 50110 "Sales Order Processor"
|
|
{
|
|
Assignable = true;
|
|
Permissions =
|
|
tabledata Customer = IM,
|
|
tabledata "Sales Header" = IMD,
|
|
tabledata "Sales Line" = IMD;
|
|
}
|
|
|
|
permissionset 50111 "Sales Viewer"
|
|
{
|
|
Assignable = true;
|
|
Permissions =
|
|
tabledata Customer = R,
|
|
tabledata "Sales Header" = R,
|
|
tabledata "Sales Line" = R;
|
|
}
|