[Validation only - do not merge] API auth uptake checkpoint - #11861
Prangshuman Das (t-prda) wants to merge 218 commits into
Conversation
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Restore exclusions unrelated to the authentication bridge and retain representative GET, POST, PATCH, and E-Document coverage. AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Honor RequiredTestIsolation=Disabled for Integration tests and re-enable the Expense Agent API coverage. AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
This reverts commit 351b416.
Run the read-only API scenarios under the existing Codeunit-isolated Integration pass. AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Retain the 22 Expense API scenarios proven under Codeunit isolation while deferring two setup-visibility cases. AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Limit the pull-request matrix while iterating on API test coverage. Remove before merge. AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Avoid treating unrelated disabled capabilities as project capability failures. AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Keep the temporary W1 project filter without disabling incremental baseline resolution. AB#646383 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
The historical workflow patch relocated the original core checks. Remove that duplicate while retaining the behavioral workflow tests and downstream AL adoption metadata assertions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
|
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Keep all workflow behavior tests and the clean-codeunit activation setting. The test file now matches the workflow parent. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Keep the activity-log fixture independent of approval-limit defaults; leave production defaults and shared test-user helpers unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
…exclusion Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Good Sense Reviewer - Round 1Recommendation: Reject ChangesWhat this PR doesThis checkpoint carries protected API test credentials, clean-tenant execution, shared authentication and date setup, and broad API-suite re-enablement. The technical changes address the authentication failure, and the available execution evidence supports the approach. However, this is explicitly a validation-only checkpoint that duplicates the intended implementation head and must not be merged through this channel. Problem-solution fitFit: Strong Shared authentication gives the re-enabled Graph tests access to the generated UserPassword credential. The isolation and fixture changes support running those suites reliably. SuggestionsS1 (🟠 Moderate): Start the mount timeout after the database copy Risk assessment and necessityRisk: The change spans credential lifetime, tenant database replacement, parallel scheduling, and many API test fixtures. Current UserPassword validation is strong, but Windows-authenticated runtime remains unverified, and slow database copies can consume the tenant mount timeout. Necessity: The authentication and test re-enablement work is necessary. This validation checkpoint is not a valid merge vehicle; the implementation should land through its intended integration path.
|
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Remove the wrapper generator and its generator-specific tests. Keep the shared finalizer and behavioral tests that execute every project wrapper. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Validation only - do not merge
AB#646383
Validate the exact AL uptake before business-fix layers at review #11860. The tree matches that review branch; a forward-only validation merge preserves its historical ancestry, so commit heads differ; there are no validation-only code changes. This main-targeted draft remains outside native stack #11893 and must not be merged or auto-merged.
Review order: #10085 auth core -> #11862 URL/fixture prerequisites -> #11891 workflow infrastructure -> #11860 AL uptake -> #11224–#11230 -> #11322 -> #11451–#11454.
Main-target validation preserves warning-baseline policy. Previously observed missing feature-base baselines and the later stale-main AS0059 findings are different failures; neither is suppressed.
HTTP validation target
Separate uptake-owned CU139496
API Test Auth HTTP TestscontainsMicrosoftAuthenticationRespectsServerAuthMode: the same three real OData service-document requests must return 401/200/401 for UserPassword or 200/200/200 for authorized ambient Windows authentication, in default None / Microsoft / deselected None order. A helper selects only the expected ambient status; the test body executes all three requests with unconditional assertions. The OnPrem constraint remains; no environment is silently skipped. Windows runtime is unverified until tested in an actual Windows-authenticated environment. The existing HTTP request helper executes the requests; no credentials are printed and no public production test event is added. The scenario reads the existing endpoint without fixture writes or new isolation metadata. Its own codeunit boundary prevents the three URL metadata-writing tests in CU139494 from retaining transaction state into the HTTP request; all 11 auth/URL tests remain unchanged. The HTTP scenario uses response assertions only, without mock-event recording assertions. It belongs here because #11891 provisions the container password; core remains runnable before that infrastructure. The Key Vault fallback alone cannot supply AL-Go's random container password.Clean-codeunit execution is explicitly enabled by uptake's
enableCleanTestCodeunitExecution: true; auth adoption and new lane activation remain coupled.Validation limits
The previous UserPassword HTTP 401/200/401 result is historical after this reconciliation. CU139496
MicrosoftAuthenticationRespectsServerAuthModestill executes all three requests; Windows200/200/200 runtime remains unverified. The workflow clean-codeunit gate stays default-off and uptake stays explicitly enabled. No provider, authentication contract, new public event, NAV selector or foreign NST change was introduced. Excluded PDF cases and absent/excluded country/native cases remain unverified; prior tolerated-native results are not universal passes. The 59 owned re-enabled methods cover the reviewed fixes, not59 distinct product defects. Validation drafts remain Do Not Merge, outside native stack #11893.Current checkpoint
Head
ef20ad38eae6769b76516051e5f0c53a2596de8d, tree7600c7269e268f7c320ac9efee9b641dbc5003b4; parentdcc07337b9b859d9f88ad22a9cd4b30c222aeab6.Forward-integrated captured main
bb7111877ff786951b86a1a0f80d8b39b8f5dacd, including upstream CLEAN27 removal82b11d26c073de93df3aab17434069f72feab640(PR12066), to align the direct stacked-PR warning gate. The prior direct uptake checkout retained obsolete source while warning-reference run37020063048 used main73d5794e; RU and CH therefore each reported51 additional warnings (36 AA0244,15 AA0218). Main-targeted RU validations already passed with cleaned source. No warning suppression, parameter rename, partial cherry-pick, or comparator change was made.Local Pester:117 passed, zero failed/skipped at exact workflow, uptake and full heads. Every layer retains its exact owned patch; all changed baseline blobs equal captured main, and all remaining blobs—including exclusions—are unchanged. The23 committed wrappers/shared success-only finalizer, generator removal, current-process credential identity, ACLs, buffer clearing and narrowed platform classifier remain intact; ordinary configured reruns are unchanged.
Accepted cleanup limitation: failed/cancelled runs rely on normal container teardown; no hard-runner-loss guarantee. Normal CI uses per-run disposable credentials, but supplied credentials may differ. Hook logs prove invocation, not necessarily explicit deletion if teardown already removed the file.
Uptake retains the five query-safe URL compositions in CU148343
StandardSubmissionExposesPolicySnapshot, all assertions,8 methods, setup restoration and the single unlimited-approval fixture. Workflow remains default-off; uptake enables clean execution. Auth visibility/provider contracts and HTTP scenario are preserved. Upstream shared Spend Request zero-amount UnitTest semantics and permission cleanup from PR11561 remain unchanged. CU139806TestGetCompanyAndEnvironmentDescriptionsstays excluded pending its original rationale/current NAV verification (PR11741).Fresh exact-head GitHub CI is pending, not passed. Previous runs are historical for these new commits. Verify all8 activity methods across22 countries if present; Windows runtime and excluded PDF/native coverage remain unverified. Only this captured main was integrated—no repeated baseline chasing. Merged prefix/native stack #11893 and draft/ready states remain unchanged; validation drafts remain Do Not Merge.