fix(AC0031): treat object-level AccessByPermission as permission coverage - #567
Merged
Merged
Conversation
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…rage Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ission is still reported when unused Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A report with
AccessByPermission = tabledata "Incoming Document" = RM;and a dataitem on that table gets AC0031 ("does not declare permission 'r' for tabledata 'Incoming Document'"). The object already states that it is only meant for users who hold that permission on the table, so the Info-level suggestion to addPermissionsnext to it is noise.Platform facts
Permissionsgrants the object extra table permissions at runtime.AccessByPermissionis only a UI-visibility mask: the report or page is removed from Tell Me, menus and role centers when the user lacks the mask. It grants nothing and does not change the runtime data-access checks.Binder.BindPermissionPropertyValue, so the value is aPermissionPropertyValueSyntaxin both cases. Outside permission sets the SDK upper-cases the chars, so casing carries no meaning. The object-level property is registered only for pages and reports.RIMDthe user needs at least one char). It applies only when UI Elements Removal isLicenseFileorLicenseFileAndUserPermissions, and the object can still be run from code or aRunObjectaction.Change
PermissionResolver.IsCoverednow also reads the object-levelAccessByPermissionproperty through the existingObjectPermissionCovers. That method already filters totabledata, matches the table by name, qualified name or ID, and compares chars case-insensitively. AddsEnumProvider.PropertyKind.AccessByPermission. AC0032 is unchanged.tabledataonly.AccessByPermission = table X = X(permission to run the object) does not cover data operations.RDcoversrandd; aModify()in the same object is still reported.AccessByPermissionstay out of scope.AccessByPermissionis neither aPermissionsentry nor a table use. APermissionsentry that duplicates the mask is still reported when the table is never accessed (pinned by a fixture).Corpus evidence (Base App W1 28.5)
29 reports and 31 pages declare an object-level
AccessByPermission = tabledata. 18 of those 29 reports have a dataitem on that table, and none of the 18 also declaresPermissionsfor it. Report 299 "Delete Invoiced Sales Orders" (AccessByPermission = TableData "Sales Header" = RD;) has exactly the shape reported in the issue. The object-leveltable X = Xform does not occur in the corpus.Tests
RDplusDelete()inOnAfterGetRecord, a page whose mask names a table other than itsSourceTable, and a lowercase mask.RplusModify()), a mask on a different table, and thetable X = Xform.Permissionsentry is not reported; a mask does not count as a table use; a duplicated but unused entry is still reported.dotnet test ALCops.slnis green.dotnet format --verify-no-changesis clean. Common and ApplicationCop build for netstandard2.1, net8.0 and net10.0 with no warnings.Review
/code-review highreported no correctness findings. It raised two other findings:Permissionsentry duplicating the mask is suppressed. The bullet now describes the actual behaviour, and theReportAccessByPermissionDuplicateUnusedHasDiagnostic fixture pins it..vscode/Copy-BinToALAnalyzers.ps1. No action: that file is an unrelated uncommitted local change and is not part of this branch.Docs: ALCops/alcops.dev#192
Closes #312
🤖 Generated with Claude Code