bcquality/microsoft/knowledge/security/validatetablerelation-false-on-user-input.md
Jesper Schulz-Wedde ec8f891954 Correct security and privacy guidance
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9c2eebc4-dcd5-4b85-8113-90772d818900
2026-07-14 10:45:42 +02:00

1.3 KiB

bc-version domain keywords technologies countries application-area
all
security
validatetablerelation
tablerelation
field
validation
input
al
w1
all

Handle free-form input when ValidateTableRelation is false

Description

ValidateTableRelation = false intentionally lets a user keep free-form input even when it does not match TableRelation. This is supported for scenarios such as accepting a new vendor name and handling it in OnValidate. The risk is not the property itself; it is leaving downstream code to assume that every value identifies an existing related record.

Best Practice

Keep the default validation when values must exist in the related table. When free-form values are intentional, set both ValidateTableRelation = false and TestTableRelation = false, then add compensating OnValidate logic that normalizes, validates, creates, or otherwise handles unmatched input. Document that downstream code must not assume the relation exists. See sample: validatetablerelation-false-on-user-input.good.al.

Anti Pattern

ValidateTableRelation = false on a user-facing field with no intentional handling for unmatched values, or leaving TestTableRelation = true so database relation tests reject values the UI deliberately accepts. See sample: validatetablerelation-false-on-user-input.bad.al.