Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
8514487
Keep Expense permission observations restricted and assertions execut…
t-prda Sep 14, 2026
aef6182
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 15, 2026
a181728
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 15, 2026
bcb5ddd
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 15, 2026
9b6f42c
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 15, 2026
df667ac
Reconcile expense permission tests with upstream Entra coverage
t-prda Sep 24, 2026
4f5edae
Carry expense-permission-tests forward after separating workflow infr…
t-prda Sep 25, 2026
a6385e3
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
4751396
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
2142d18
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
4a4b0f8
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
184ed4d
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
ef2e003
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
46d60ce
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
08a43f0
Refresh expense-permission-tests layer with the reviewed auth base
t-prda Sep 25, 2026
613fd2f
Reconcile restricted permission observations with upstream setup-role…
t-prda Sep 30, 2026
25cc72b
Propagate removal of uptake-only AL source inspection tests
t-prda Sep 30, 2026
4f59b07
Propagate explicit activity-log fixture approval permission
t-prda Sep 30, 2026
595231b
Propagate refreshed baseline and retain upstream company-description …
t-prda Sep 30, 2026
e716055
Propagate platform-race classifier regression fix
t-prda Oct 2, 2026
c7af52b
Propagate platform-race classifier regression fix
t-prda Oct 2, 2026
c338027
Propagate supported API credential finalizer
t-prda Oct 2, 2026
16828a8
Propagate current baseline and simplified API credential finalizer
t-prda Oct 2, 2026
7c2b4a7
Propagate query-safe policy snapshot API test URLs
t-prda Oct 2, 2026
460383d
Propagate warning-baseline alignment without changing scoped fixes
t-prda Oct 2, 2026
f3439a6
Propagate tenant-help correction and isolated policy response buffers
t-prda Oct 4, 2026
40dd7ea
Reconcile captured upstream activity-log coverage while preserving AP…
t-prda Oct 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -139,20 +139,29 @@ codeunit 148338 "Expense Permissions Test"
ExpenseUser: Record "Expense User";
Approver: Record "Expense User";
TravelRequestApproval: Codeunit "Travel Request Approval";
ExpenseUserCanRead: Boolean;
PermissionErrorCode: Text;
PermissionErrorText: Text;
begin
// [SCENARIO] An employee-only caller cannot approve requests without access to Expense User data.
Initialize();
CreateTravelRequestApprovalScenario(SpendRequest, ExpenseUser, Approver);
// Preserve the fixture for the post-denial checks when asserterror rolls back.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

$\textbf{🟠\ High\ Severity\ —\ Testing}$

The test adds an explicit Commit() but has no TransactionModel attribute, so it uses the test framework's AutoRollback default and can fail at the commit instead of validating the permission-denial behavior. Assign an appropriate transaction model for this committed fixture setup and ensure the test runner provides isolation for the committed data.

Knowledge:

👍 useful · ❤️ especially valuable · 👎 wrong - reply with why · AL review agent v1.47.6

Commit();

LibraryLowerPermissions.StartLoggingNAVPermissions();
SetCallerPermissions(EmployeeOnlyPermissionSetTok, ExpenseUser);
LibraryLowerPermissions.SetExactPermissionSet(EmployeeOnlyPermissionSetTok);
ExpenseUserCanRead := ExpenseUser.ReadPermission();
asserterror TravelRequestApproval.Approve(SpendRequest, Approver."No.");
Assert.ExpectedErrorCode('DB:ClientReadDenied');
Assert.ExpectedError(ExpenseUser.TableCaption());
// Capture the denial before permission cleanup can change the last-error state.
PermissionErrorCode := GetLastErrorCode();
PermissionErrorText := GetLastErrorText();
RestoreFullPermissions();
LibraryLowerPermissions.StopLoggingNAVPermissions();

Assert.AreEqual('DB:ClientReadDenied', PermissionErrorCode, 'Approval must fail because Expense User read access is denied.');
Assert.ExpectedMessage(ExpenseUser.TableCaption(), PermissionErrorText);
Assert.IsFalse(ExpenseUserCanRead, 'The caller must not have direct access to Expense User.');
SpendRequest.Get(SpendRequest."No.");
Assert.AreEqual(SpendRequest.Status::Released, SpendRequest.Status, 'A denied approval must preserve the request status.');
ExpenseReportHeader.SetRange("Spend Request No.", SpendRequest."No.");
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -149,11 +149,6 @@
"codeunitName": "Expense Permissions Test",
"method": "ExpenseAgentCanUpdateTravelRequestDetailsIndirectly"
},
{
"codeunitId": 148338,
"codeunitName": "Expense Permissions Test",
"method": "TravelRequestApprovalFailsWithoutExpensePermissions"
},
{
"codeunitId": 148339,
"codeunitName": "Spend Request Test",
Expand Down
Loading