[Validation only - do not merge] Combined API auth and Expense fix stack - #11455
Draft
Prangshuman Das (t-prda) wants to merge 619 commits into
Draft
Prangshuman Das (t-prda) wants to merge 619 commits into
Prangshuman Das (t-prda) wants to merge 619 commits into
Conversation
This was referenced Sep 14, 2026
Anders (AndersLarsenMicrosoft)
deployed
to
triage
September 17, 2026 09:09 — with
GitHub Actions
Active
This was referenced Sep 24, 2026
…rastructure Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
…structure Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
…ructure Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Retain the six AL contracts and the pre-existing Graph OnRun; remove auth source-pattern checks. Keep private file-secret lookup out of session-wide Key Vault state. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Includes upstream permission cleanup fix #11561 and current artifact/baseline settings; preserve reviewed opt-in authentication without warning suppression. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Remove the wrapper generator and its generator-specific tests. Keep the shared finalizer and behavioral tests that execute every project wrapper. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Validation only - do not merge
AB#646383
Validate the exact full cumulative business-fix stack at review #11454. The tree matches that review branch; a forward-only validation merge preserves its historical ancestry, so commit heads differ; there are no validation-only code changes. This main-targeted draft remains outside native stack #11893 and must not be merged or auto-merged.
Review order: #10085 auth core -> #11862 URL/fixture prerequisites -> #11891 workflow infrastructure -> #11860 AL uptake -> #11224–#11230 -> #11322 -> #11451–#11454.
Main-target validation preserves warning-baseline policy. Previously observed missing feature-base baselines and the later stale-main AS0059 findings are different failures; neither is suppressed.
HTTP validation target
Separate uptake-owned CU139496
API Test Auth HTTP TestscontainsMicrosoftAuthenticationRespectsServerAuthMode: the same three real OData service-document requests must return 401/200/401 for UserPassword or 200/200/200 for authorized ambient Windows authentication, in default None / Microsoft / deselected None order. A helper selects only the expected ambient status; the test body executes all three requests with unconditional assertions. The OnPrem constraint remains; no environment is silently skipped. Windows runtime is unverified until tested in an actual Windows-authenticated environment. The existing HTTP request helper executes the requests; no credentials are printed and no public production test event is added. The scenario reads the existing endpoint without fixture writes or new isolation metadata. Its own codeunit boundary prevents the three URL metadata-writing tests in CU139494 from retaining transaction state into the HTTP request; all 11 auth/URL tests remain unchanged. The HTTP scenario uses response assertions only, without mock-event recording assertions. It belongs here because #11891 provisions the container password; core remains runnable before that infrastructure. The Key Vault fallback alone cannot supply AL-Go's random container password.Clean-codeunit execution is explicitly enabled by uptake's
enableCleanTestCodeunitExecution: true; auth adoption and new lane activation remain coupled.Historical targeted country evidence
Historical before this parent reconciliation; not new-head proof.
Final full-stack artifacts at
da6d82d6c8cf7c64bbd7355ca0acab28f0d5e28averify IT 3/3 (Italian discount1 + quote dates2), CZ 14/14 (journal numbering2 + VAT12), AU 22/22 (cancellation10 + VAT12). Each listed method passed exactly once in its country artifact from run36162564729. These are targeted country checks, not a claim about excluded PDF/native cases or Windows authentication.Validation limits
The previous UserPassword HTTP 401/200/401 result is historical after this reconciliation. CU139496
MicrosoftAuthenticationRespectsServerAuthModestill executes all three requests; Windows200/200/200 runtime remains unverified. The workflow clean-codeunit gate stays default-off and uptake stays explicitly enabled. No provider, authentication contract, new public event, NAV selector or foreign NST change was introduced. Excluded PDF cases and absent/excluded country/native cases remain unverified; prior tolerated-native results are not universal passes. The 59 owned re-enabled methods cover the reviewed fixes, not59 distinct product defects. Validation drafts remain Do Not Merge, outside native stack #11893.Current checkpoint
Head
8bfbe2a6a1b6bfbad2fc8f62872c458e8b37e23a, tree6d45a55cb2c7753628b3e76d355727749a2c9744; parentf00136d9bc6361dad8cdebcb4847463dcee7e9d4.Focused policy-snapshot URL repair: the new upstream CU148343
StandardSubmissionExposesPolicySnapshotappended report/action paths after the tenant query and used a second?for history filters. It now uses the existing query-preserving path/query helpers for all five compositions. No authentication-init move, retry relaxation, assertions removed, or production changes. The eight methods, setup restoration, unlimited-approval fixture, category escaping and participation-history checks remain unchanged.Observed baseline failure: FI/NZ/W1 Integration in run37011144022 returned POST401
Authentication_InvalidCredentialsfor this method. URI parsing reproduces the corrupted tenant value; this is a test URL defect, not a transient platform-race classification. Local Pester:117 passed, zero failed/skipped at exact uptake/full heads. Each of13 cumulative layers differs from its previous head in this one test method only; all other source/settings/exclusion/security blobs are unchanged. No main refresh.Workflow11891 and workflow-validation11892 are untouched. Cleanup remains23 committed wrappers/shared success-only
PipelineFinalize, without a generator; failed/cancelled runs rely on normal teardown, with no hard-runner-loss guarantee. The narrowed platform classifier and ordinary configured rerun policy remain unchanged. Private auth-provider behavior, public context, HTTP scenario and clean-execution stage boundary are preserved.Fresh exact-head GitHub CI is pending, not passed. All8 CU148343 methods need verification (176 cases if all22 countries run); the earlier154-case evidence is historical. Windows runtime and excluded PDF/native coverage remain unverified. CU139806
TestGetCompanyAndEnvironmentDescriptionsstays excluded pending original rationale/current NAV verification (upstream PR11741). Permission cleanup from PR11561, all upstream exclusion metadata and native stack #11893 are retained. Validation drafts remain Do Not Merge.