bcquality/community/knowledge/security/secrets-isolated-storage.md
Jeremy Vyska f5156c61de Add 15 community knowledge articles from BC Code Intel ingest
Ingests net-new /community knowledge from BC Code Intelligence, surviving
the admission test, gray-zone salvage, and dedup against the full corpus.

Domains: ui (6), error-handling (3), performance (2), upgrade (1),
appsource (1), security (1), telemetry (1). The two BC24 No. Series
migration drafts are merged into one article.

Adds good/bad AL samples for the clean-fit articles (error-handling,
performance, security, telemetry). UI and appsource remain knowledge-only.

Validator and knowledge-index checks pass (207 articles).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 11:02:48 +02:00

1.8 KiB

bc-version domain keywords technologies countries application-area
all
security
isolatedstorage
secrets
api-key
oauth-token
connection-string
table-field
credentials
al
w1
all

A secret belongs in IsolatedStorage, never in a table field

Contributions welcome — open a PR to refine or extend this article.

Description

API keys, OAuth tokens, client secrets, and connection strings must not be stored in an ordinary table Text field — not even on a hidden setup table. A regular field is exposed through record reads, page display, RapidStart and Excel export, report datasets, and surfaces in DataClassification review; anyone with table permission can read it. The correct home is IsolatedStorage, which is invisible to database queries, API pages, and configuration packages. The storage-location decision is the rule here; how to scope and encrypt the value once it is in IsolatedStorage is covered separately.

Best Practice

Persist every credential with IsolatedStorage, write it at the point of capture, and read it only when needed. For the per-secret details — choosing the right DataScope, encrypting at rest, and typing the value as SecretText so it cannot leak into logs — follow isolatedstorage-datascope-module-vs-company, isolatedstorage-setencrypted-for-sensitive-values, and secrettext-for-credentials.

Anti Pattern

A "Setup" or "Connection" table carrying a Text field named API Key, Password, or Client Secret. The value is now readable by any object with table permission, ships in RapidStart packages and Excel exports, and appears in record snapshots — a credential disclosure that no amount of encryption-in-transit elsewhere makes up for. Reviewer signal: a secret-shaped field declared on a table instead of an IsolatedStorage call.