bcquality/community/knowledge/security/protect-sensitive-data-in-temporary-tables.good.al
Jeremy Vyska 47a189e61c Seed community performance and security knowledge
Ports 14 concern-sized articles (8 performance, 6 security) and 25
AL samples from BC Code Intelligence, restructured to BCQuality's v1
schema and layered under /community/knowledge/. Each article is
atomic, under 100 lines, and ships <slug>.good.al and (where the
pattern has a clear anti-example) <slug>.bad.al siblings.

Jesper's microsoft-layer leaves (al-performance-review and
al-security-review) source across every enabled layer via
*/knowledge/<domain>/**, so these additions are picked up by the
existing action skills without any new skill definitions.

Performance (8):
  - use-deleteall-for-filtered-bulk-deletion
  - call-setloadfields-before-filters
  - load-common-fields-before-branching-on-case
  - load-only-primary-key-fields-for-reference-work
  - omit-filter-only-fields-from-setloadfields
  - choose-maintainsiftindex-by-read-write-ratio
  - avoid-growing-globals-in-singleinstance-subscribers
  - order-case-branches-by-frequency

Security (6):
  - classify-every-field-with-dataclassification
  - protect-sensitive-data-in-temporary-tables
  - guard-bulk-operations-with-istemporary
  - compose-permission-sets-with-included-sets
  - do-not-grant-rights-beyond-a-users-entitlement
  - prefer-oauth2-over-api-keys-for-external-http-calls

Graveyard-bound items (not ported; to be captured in a later
/docs/triage-graveyard.md):
  - testfield-performance (soft guidance, low actionability)
  - table-event-batch-operation-impact (keep-event-subscribers-lightweight
    already carries the core insight)
  - Most of /roger-reviewer (AL formatting - frontier-model territory)
  - sift-technology-fundamentals (descriptive, not a citable concern)
  - bc-telemetry-buddy-* (tooling promotion, not guidance)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-19 18:13:32 +02:00

32 lines
946 B
AL

codeunit 50100 "Customer Temp Processor"
{
procedure BuildScopedCustomerBuffer(CustomerNoFilter: Text): Boolean
var
Customer: Record Customer;
TempCustomer: Record Customer temporary;
begin
// Validate the caller's permission before copying sensitive rows.
if not Customer.ReadPermission() then
exit(false);
Customer.SetFilter("No.", CustomerNoFilter);
if not Customer.FindSet() then
exit(true);
repeat
TempCustomer := Customer;
TempCustomer.Insert();
until Customer.Next() = 0;
ProcessCustomerBuffer(TempCustomer);
// Explicit cleanup on the normal exit path.
TempCustomer.DeleteAll();
exit(true);
end;
local procedure ProcessCustomerBuffer(var TempCustomer: Record Customer temporary)
begin
// Use the buffer in-place; do not persist values elsewhere.
end;
}