Skip to content

[Validation only - do not merge] API auth uptake checkpoint - #11861

Draft
Prangshuman Das (t-prda) wants to merge 218 commits into
mainfrom
features/646383-api-uptake-validation
Draft

Prangshuman Das (t-prda) wants to merge 218 commits into
mainfrom
features/646383-api-uptake-validation

Conversation

@t-prda

@t-prda Prangshuman Das (t-prda) commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Validation only - do not merge

AB#646383

Validate the exact AL uptake before business-fix layers at review #11860. The tree matches that review branch; a forward-only validation merge preserves its historical ancestry, so commit heads differ; there are no validation-only code changes. This main-targeted draft remains outside native stack #11893 and must not be merged or auto-merged.

Review order: #10085 auth core -> #11862 URL/fixture prerequisites -> #11891 workflow infrastructure -> #11860 AL uptake -> #11224–#11230 -> #11322 -> #11451–#11454.

Main-target validation preserves warning-baseline policy. Previously observed missing feature-base baselines and the later stale-main AS0059 findings are different failures; neither is suppressed.

HTTP validation target

Separate uptake-owned CU139496 API Test Auth HTTP Tests contains MicrosoftAuthenticationRespectsServerAuthMode: the same three real OData service-document requests must return 401/200/401 for UserPassword or 200/200/200 for authorized ambient Windows authentication, in default None / Microsoft / deselected None order. A helper selects only the expected ambient status; the test body executes all three requests with unconditional assertions. The OnPrem constraint remains; no environment is silently skipped. Windows runtime is unverified until tested in an actual Windows-authenticated environment. The existing HTTP request helper executes the requests; no credentials are printed and no public production test event is added. The scenario reads the existing endpoint without fixture writes or new isolation metadata. Its own codeunit boundary prevents the three URL metadata-writing tests in CU139494 from retaining transaction state into the HTTP request; all 11 auth/URL tests remain unchanged. The HTTP scenario uses response assertions only, without mock-event recording assertions. It belongs here because #11891 provisions the container password; core remains runnable before that infrastructure. The Key Vault fallback alone cannot supply AL-Go's random container password.

Clean-codeunit execution is explicitly enabled by uptake's enableCleanTestCodeunitExecution: true; auth adoption and new lane activation remain coupled.

Validation limits

The previous UserPassword HTTP 401/200/401 result is historical after this reconciliation. CU139496 MicrosoftAuthenticationRespectsServerAuthMode still executes all three requests; Windows200/200/200 runtime remains unverified. The workflow clean-codeunit gate stays default-off and uptake stays explicitly enabled. No provider, authentication contract, new public event, NAV selector or foreign NST change was introduced. Excluded PDF cases and absent/excluded country/native cases remain unverified; prior tolerated-native results are not universal passes. The 59 owned re-enabled methods cover the reviewed fixes, not59 distinct product defects. Validation drafts remain Do Not Merge, outside native stack #11893.

Current checkpoint

Head ef20ad38eae6769b76516051e5f0c53a2596de8d, tree 7600c7269e268f7c320ac9efee9b641dbc5003b4; parent dcc07337b9b859d9f88ad22a9cd4b30c222aeab6.

Forward-integrated captured main bb7111877ff786951b86a1a0f80d8b39b8f5dacd, including upstream CLEAN27 removal 82b11d26c073de93df3aab17434069f72feab640 (PR12066), to align the direct stacked-PR warning gate. The prior direct uptake checkout retained obsolete source while warning-reference run37020063048 used main73d5794e; RU and CH therefore each reported51 additional warnings (36 AA0244,15 AA0218). Main-targeted RU validations already passed with cleaned source. No warning suppression, parameter rename, partial cherry-pick, or comparator change was made.

Local Pester:117 passed, zero failed/skipped at exact workflow, uptake and full heads. Every layer retains its exact owned patch; all changed baseline blobs equal captured main, and all remaining blobs—including exclusions—are unchanged. The23 committed wrappers/shared success-only finalizer, generator removal, current-process credential identity, ACLs, buffer clearing and narrowed platform classifier remain intact; ordinary configured reruns are unchanged.

Accepted cleanup limitation: failed/cancelled runs rely on normal container teardown; no hard-runner-loss guarantee. Normal CI uses per-run disposable credentials, but supplied credentials may differ. Hook logs prove invocation, not necessarily explicit deletion if teardown already removed the file.

Uptake retains the five query-safe URL compositions in CU148343 StandardSubmissionExposesPolicySnapshot, all assertions,8 methods, setup restoration and the single unlimited-approval fixture. Workflow remains default-off; uptake enables clean execution. Auth visibility/provider contracts and HTTP scenario are preserved. Upstream shared Spend Request zero-amount UnitTest semantics and permission cleanup from PR11561 remain unchanged. CU139806 TestGetCompanyAndEnvironmentDescriptions stays excluded pending its original rationale/current NAV verification (PR11741).

Fresh exact-head GitHub CI is pending, not passed. Previous runs are historical for these new commits. Verify all8 activity methods across22 countries if present; Windows runtime and excluded PDF/native coverage remain unverified. Only this captured main was integrated—no repeated baseline chasing. Merged prefix/native stack #11893 and draft/ready states remain unchanged; validation drafts remain Do Not Merge.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Restore exclusions unrelated to the authentication bridge and retain representative GET, POST, PATCH, and E-Document coverage.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Honor RequiredTestIsolation=Disabled for Integration tests and re-enable the Expense Agent API coverage.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Run the read-only API scenarios under the existing Codeunit-isolated Integration pass.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Retain the 22 Expense API scenarios proven under Codeunit isolation while deferring two setup-visibility cases.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Limit the pull-request matrix while iterating on API test coverage. Remove before merge.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Avoid treating unrelated disabled capabilities as project capability failures.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Keep the temporary W1 project filter without disabling incremental baseline resolution.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
The historical workflow patch relocated the original core checks. Remove that duplicate while retaining the behavioral workflow tests and downstream AL adoption metadata assertions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Stale Status Check Deleted

The Pull Request Build workflow run for this PR was older than 72 hours and has been deleted.

📋 Why was it deleted?

Status checks that are too old may no longer reflect the current state of the target branch. To ensure this PR is validated against the latest code and passes up-to-date checks, a fresh build is required.


🔄 How to trigger a new status check:

  1. 📤 Push a new commit to the PR branch, or
  2. 🔁 Close and reopen the PR

This will automatically trigger a new Pull Request Build workflow run.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Keep all workflow behavior tests and the clean-codeunit activation setting. The test file now matches the workflow parent.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Keep the activity-log fixture independent of approval-limit defaults; leave production defaults and shared test-user helpers unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
…exclusion

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
@alexei-dobriansky

Copy link
Copy Markdown
Contributor

Good Sense Reviewer - Round 1

Recommendation: Reject Changes

What this PR does

This checkpoint carries protected API test credentials, clean-tenant execution, shared authentication and date setup, and broad API-suite re-enablement.

The technical changes address the authentication failure, and the available execution evidence supports the approach. However, this is explicitly a validation-only checkpoint that duplicates the intended implementation head and must not be merged through this channel.

Problem-solution fit

Fit: Strong

Shared authentication gives the re-enabled Graph tests access to the generated UserPassword credential. The isolation and fixture changes support running those suites reliably.

Suggestions

S1 (🟠 Moderate): Start the mount timeout after the database copy
The 300-second mount limit also counts dismounting, database copy attempts, and retry delays. Restart the stopwatch immediately before Mount-NAVTenant so a slow copy does not shorten the time allowed for mounting.

Risk assessment and necessity

Risk: The change spans credential lifetime, tenant database replacement, parallel scheduling, and many API test fixtures. Current UserPassword validation is strong, but Windows-authenticated runtime remains unverified, and slow database copies can consume the tenant mount timeout.

Necessity: The authentication and test re-enablement work is necessary. This validation checkpoint is not a valid merge vehicle; the implementation should land through its intended integration path.


[AI-PR-REVIEW] version=1 promptVersion=4 system=github pr=11861 round=1 by=alexei-dobriansky at=2026-10-01T22:05:15.125Z lastSha=875726d09d211ec374ca4dbd3a600a1403340ce4 reviewKey=b0a19de2b5c05c61f1a87f7a95ebbf964c5fed2956c2dd9c5b68a3443adb8d39 suggestions=S1@3ae1ce99

Prangshuman Das (t-prda) and others added 12 commits October 2, 2026 13:58
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Remove the wrapper generator and its generator-specific tests. Keep the shared finalizer and behavioral tests that execute every project wrapper.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91

This branch was successfully deployed

1 active (outdated) deployment
triage — f846c7b9 Deployed Sep 28, 2026 by t-prda via Classify team ownership #5932
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AL: Apps (W1) Add-on apps for W1 Build: Automation Workflows and other setup in .github folder Build: scripts & configs Build scripts and configuration files Team: Integrations GitHub request for Integrations area

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants