bcquality/microsoft/knowledge/ui/rolecenter-permission-gating-must-use-accessbypermission.bad.al
Michael Dieringer decbf7136c Add UI knowledge: client-expression in-list and Role Center AccessByPermission
Two ui articles with compiled good/bad samples:
- page-client-expression-must-not-use-in-list: an `in [...]` list in
  Enabled/Visible/Editable/StyleExpr is rejected (AL0573 on actions,
  groups and parts; AL0322 on fields); remediate with an or-chain or a
  global Boolean, not a procedure call. Plain comparisons stay valid.
- rolecenter-permission-gating-must-use-accessbypermission: Role Center
  pages and pageextensions of them cannot host triggers/procedures
  (AL0378/AL0569); gate parts by permission with AccessByPermission,
  with the UI Elements Removal and non-security-boundary caveats.

Wired into al-ui-review worklist tokens and high-signal mappings, and
registered both pairs in the ui review-fixtures override.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 23:14:09 +02:00

23 lines
652 B
AL

pageextension 50710 "Sample Bus. Mgr. RC Ext" extends "Business Manager Role Center"
{
layout
{
addafter(Control16)
{
part(SampleReportInbox; "Report Inbox Part")
{
ApplicationArea = Basic, Suite;
// AL0573: procedure calls are not valid for client expressions.
Visible = CanSeeReportInbox();
}
}
}
// AL0569: a page of type Role Center cannot have procedures.
local procedure CanSeeReportInbox(): Boolean
var
ReportInbox: Record "Report Inbox";
begin
exit(ReportInbox.ReadPermission());
end;
}