bcquality/community/knowledge/security/guard-bulk-operations-with-istemporary.md
Jesper Schulz-Wedde 9a4198eb28 Add [all] sentinel to bc-version; apply to version-agnostic knowledge
Most of the corpus — FindSet/SetLoadFields/CalcFields patterns, permission
sets, SingleInstance codeunits, DataClassification, IsolatedStorage,
transaction scope, SecretText — describes BC platform behaviour that is
identical across supported versions. The seed [26..28] range on every
file implied a version-specificity the content does not actually have,
and there was no way to express "applies to every version" in the
schema the way [w1] and [all] already do for countries and
application-area.

Extend the v1 schema with a universal sentinel for bc-version, parallel
to the sentinels already defined for the other dimensions:

  bc-version: [all]         # applies to every BC version

[all] is mutually exclusive with explicit versions. Range shorthand
([26..28]) and explicit lists ([26, 27, 28]) continue to work for files
genuinely tied to a version-gated API or deprecation.

Update read.md (field definition, matching semantics, partial-context
rule), write.md (default to [all], use ranges only with a concrete
reason), README.md (frontmatter example), and the CI validator. All
forty existing knowledge files and the three action skills convert to
[all]; none of the current content is version-gated. Validator passes.
2026-04-23 16:00:03 +02:00

1.6 KiB

bc-version domain keywords technologies countries application-area
all
security
istemporary
deleteall
modifyall
safeguard
precondition
al
w1
all

Guard bulk operations with IsTemporary

Seed article. Ported from BC Code Intelligence to seed the community corpus. Community contributors are invited to expand or refine.

Description

An AL helper that accepts a var Rec: Record X parameter and performs a bulk operation (DeleteAll, ModifyAll, or an unfiltered loop that mutates every record) cannot tell from the signature alone whether the caller passed a temporary buffer or the real table. A misuse that passes the real table wipes or rewrites live data at production scale with no earlier warning. A single IsTemporary check at the procedure entry turns a silent-corruption risk into an early, actionable failure.

Best Practice

Any helper designed to operate on a temporary record, and that performs DeleteAll, ModifyAll, or similar bulk writes on its parameter, should call Rec.IsTemporary() at the top and raise a descriptive error when the assumption is violated. The error message should name the parameter so the misuse is easy to locate.

See sample: guard-bulk-operations-with-istemporary.good.al.

Anti Pattern

Trusting documentation or naming conventions alone to signal that a var Rec parameter is expected to be temporary. A future refactor or a copy-paste caller can pass the real table; the bulk operation then executes against production rows silently.

See sample: guard-bulk-operations-with-istemporary.bad.al.