bcquality/microsoft/knowledge/privacy/avoid-strsubstno-prebuild-before-error.md
Jesper Schulz-Wedde aca3986fd0
Correct security and privacy knowledge guidance (#92)
* Correct security and privacy guidance

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9c2eebc4-dcd5-4b85-8113-90772d818900

* Address security privacy review findings

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9c2eebc4-dcd5-4b85-8113-90772d818900

---------

Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
2026-07-14 11:25:03 +02:00

1.4 KiB

bc-version domain keywords technologies countries application-area
20..
privacy
strsubstno
error
telemetry
pii
prebuild
text-variable
al
w1
all

Pass a Label directly as the first Error argument

Description

Error method trace telemetry includes the AL error string only when the first Error argument is a Label or TextConst. Wrapping a label in StrSubstNo, or concatenating labels or text, produces a dynamic Text first argument. In that case the actual string is not emitted as the telemetry message; the platform emits its generic guidance instead. CodeCop AA0231 flags both shapes because the label identity and data-classification context are lost.

Best Practice

Declare the complete message as a Label or TextConst and pass it directly to Error, followed by substitution values. The client receives the formatted message while telemetry can retain the static message template without using the dynamic values as its message. See error-direct-substitution-safe-for-telemetry.md.

See sample: avoid-strsubstno-prebuild-before-error.good.al.

Anti Pattern

Error(StrSubstNo(CustomerInvalidErr, Customer."No.")) and Error(HeaderErr + DetailErr) both make the first argument dynamic. They reduce error telemetry quality; they do not cause that composed string to be logged verbatim as the telemetry message.

See sample: avoid-strsubstno-prebuild-before-error.bad.al.