mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 06:36:55 +01:00
* Avoid Public Event publisher * knowledge(events): scope public-publisher detection to same-app raisers The detection rule flagged every public event publisher, including ones deliberately public so a sibling app can raise them - a contract `internal` cannot express across app boundaries. Scope the finding to publishers that are public although only their own app raises them, and record the cross-app case as a valid Best Practice option. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0b67b90d-e4b4-4b92-9684-726c72c43b3f --------- Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0b67b90d-e4b4-4b92-9684-726c72c43b3f
38 lines
1.4 KiB
AL
38 lines
1.4 KiB
AL
// Demonstration only. Shows the wrong pattern: raising the integration event inside a TryFunction body.
|
|
|
|
codeunit 50116 "Payment Processor Bad"
|
|
{
|
|
[IntegrationEvent(false, false)]
|
|
local procedure OnBeforeSubmitPayment(var PaymentAmount: Decimal; var Cancel: Boolean)
|
|
begin
|
|
end;
|
|
|
|
procedure SubmitPayment(PaymentAmount: Decimal)
|
|
var
|
|
Success: Boolean;
|
|
begin
|
|
// TryFunction wraps both the event raise and the gateway call.
|
|
Success := TrySubmitPaymentInternal(PaymentAmount);
|
|
if not Success then
|
|
Error('Payment gateway call failed. Check connectivity and retry.');
|
|
end;
|
|
|
|
[TryFunction]
|
|
local procedure TrySubmitPaymentInternal(PaymentAmount: Decimal)
|
|
var
|
|
Cancel: Boolean;
|
|
Client: HttpClient;
|
|
Response: HttpResponseMessage;
|
|
begin
|
|
Cancel := false;
|
|
// BAD: event raised inside TryFunction. Any Error() thrown by a subscriber is caught here
|
|
// and silently swallowed - the subscriber's error never reaches the caller.
|
|
// A subscriber setting Cancel := true is also lost when TryFunction returns false.
|
|
OnBeforeSubmitPayment(PaymentAmount, Cancel);
|
|
if Cancel then
|
|
exit;
|
|
Client.Get('https://payments.example.com/submit?amount=' + Format(PaymentAmount), Response);
|
|
if not Response.IsSuccessStatusCode() then
|
|
Error('HTTP %1', Response.HttpStatusCode());
|
|
end;
|
|
}
|