bcquality/microsoft/knowledge/web-services/disable-write-operations-on-read-only-api-pages.bad.al
Jesper Schulz-Wedde 13f47f65a8
Seed web-services (API v2) knowledge domain (#45)
* Seed web-services (API v2) knowledge domain

Add eight web-services API page knowledge articles (each with .good.al/.bad.al samples), a new al-web-services-review leaf skill, and wire it into al-code-review and the README.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Trim web-services domain to 6 non-duplicative articles

Drop API entity-naming/camelCase and DelayedInsert articles (owned by the style domain). Reframe the committed-data and API-versioning articles to stay strictly within the endpoint design/behavior lane, and update the leaf skill's worklist tokens and Output example accordingly.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-25 12:37:40 +02:00

38 lines
1.1 KiB
AL

// Intended for read-only consumption, but the CRUD guards are omitted. With
// InsertAllowed/ModifyAllowed/DeleteAllowed left at their writable defaults the
// endpoint silently accepts POST, PATCH, and DELETE, so a client can mutate or
// remove ledger data this API was never meant to expose for writing.
page 50357 "WS Read Only Bad"
{
PageType = API;
APIPublisher = 'contoso';
APIGroup = 'reporting';
APIVersion = 'v1.0';
EntityName = 'customerLedgerEntry';
EntitySetName = 'customerLedgerEntries';
ODataKeyFields = SystemId;
SourceTable = "Cust. Ledger Entry";
layout
{
area(content)
{
repeater(records)
{
field(id; Rec.SystemId)
{
Caption = 'id';
Editable = false;
}
field(entryNumber; Rec."Entry No.")
{
Caption = 'entryNumber';
}
field(postingDate; Rec."Posting Date")
{
Caption = 'postingDate';
}
}
}
}
}