bcquality/microsoft/knowledge/privacy/getlasterrortext-customer-content-in-errors.md
Jesper Schulz-Wedde ec8f891954 Correct security and privacy guidance
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9c2eebc4-dcd5-4b85-8113-90772d818900
2026-07-14 10:45:42 +02:00

1.4 KiB

bc-version domain keywords technologies countries application-area
20..
privacy
getlasterrortext
error
strsubstno
telemetry
customer-data
attachment
al
w1
all

Treat GetLastErrorText() as potential customer content

Description

GetLastErrorText() can contain customer content such as field values, record keys, and file names. When it is passed as a substitution value to an Error whose first argument is a Label or TextConst, the label supplies the Error method trace telemetry message. If StrSubstNo or concatenation makes GetLastErrorText() part of the first argument, the actual dynamic string is not emitted as that telemetry message; telemetry uses generic guidance instead.

Best Practice

Use a generic label when the user does not need the underlying detail. If showing the detail is appropriate, put %1 in a label and pass GetLastErrorText() as a separate argument. This preserves a useful static telemetry message while keeping the dynamic value out of the telemetry message field.

See sample: getlasterrortext-customer-content-in-errors.good.al.

Anti Pattern

Error(StrSubstNo(AttachmentFailedErr, GetLastErrorText(true))) or Error(AttachmentPrefixErr + GetLastErrorText(true)). Both lose the static first argument and trigger AA0231; neither causes the composed text to be logged verbatim as the Error telemetry message.

See sample: getlasterrortext-customer-content-in-errors.bad.al.