Skip to content

[API tests] Provision credentials and clean-tenant workflow infrastructure - #11891

Open
Prangshuman Das (t-prda) wants to merge 12 commits into
mainfrom
features/646383-api-test-workflow
Open

Prangshuman Das (t-prda) wants to merge 12 commits into
mainfrom
features/646383-api-test-workflow

Conversation

@t-prda

@t-prda Prangshuman Das (t-prda) commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Scope

AB#646383

Workflow-only prerequisite above #11862 and below #11860: 33 .github/build files including the committed project finalizer wrappers.

  • Atomic protected credential-file materialization and cleanup, with cleared temporary buffers and consumers stopped before deletion.
  • Secondary-tenant Disabled-isolation discovery/restoration and clean-codeunit worker resets.
  • Clean-codeunit execution is opt-in via enableCleanTestCodeunitExecution. This infrastructure stage leaves it absent/off, preserving ordinary typed/Legacy execution and the existing Unit Disabled pass, including warmup and retries. Uptake [API tests] Adopt shared authentication and re-enable scoped AL tests #11860 activates it alongside AL authentication adoption.
  • Existing Legacy lanes, selectors, result aggregation and retry policy remain; Task Scheduler stays limited to the existing Uncategorized profile.
  • Behavioral PowerShell/ACL coverage of credential lifetime, discovery, scheduling, retries and result merging.

All AL source and exclusions equal the integrated main baseline bb7111877ff786951b86a1a0f80d8b39b8f5dacd, including merged auth/prerequisites. No provider adoption or API re-enablement belongs here. The old Expense helper remains until uptake.
The six relocated source-pattern auth checks are removed here too; the three additional uptake AL source-inspection assertions were also removed. No replacement auth source-pattern checks are added.

The previous workflow-only NZ Integration run newly dispatched API Disabled-isolation codeunits before authentication adoption: CU139700 has 22 failures in its JUnit, while unchanged-core NZ has no CU139700 suite and no failures. These are real runtime regressions, not infra failures or tolerated-native evidence. The default-off gate restores the stage boundary; enabled uptake/full behavior remains equivalent to the previous combined implementation. The earlier workflow run succeeded; that evidence is historical after this baseline refresh.

Native stack #11893: #10085 auth core -> #11862 URL/fixture prerequisites -> #11891 workflow infrastructure -> #11860 AL uptake -> #11224–#11230 -> #11322 -> #11451–#11454. Main-targeted draft #11892 stays outside grouping.

Validation limits

Historical uptake/full runs verified CU139496 MicrosoftAuthenticationRespectsServerAuthMode in the actual UserPassword fixture (401/200/401). The Windows 200/200/200 expectations are implemented but Windows runtime remains unverified; no foreign local NST was used. Successful GitHub runs do not establish universal native NAV coverage. Excluded PDF cases, country-specific absent/excluded cases and tolerated-native distinctions are not claimed passing. No additional PR was merged or auto-merged during this refresh; validation drafts remain Do Not Merge outside stack #11893.

Historical targeted country evidence

Final workflow NZ Integration artifact at 9269e3df582704881a898e19029308e9296cbbf1 verifies 2,751 test cases, zero failures, and CU139700 absent. This confirms the default-off gate no longer prematurely runs the API Items codeunit that previously had 22 failures. Workflow run36157073629 succeeded with all113 test jobs.

Current checkpoint

Head 69df41756d918a516a3c868ca66f45cbfd320428; captured main eaddd6b3c518414f372154ea6cedd6c12b287359.

Validation BLOCKED; no whole-run or all-country green claim. Current exact-head AL runs: workflow, workflow validation, uptake, uptake validation, full. Remaining jobs are not cancelled.

Platform 30.0.55429.0 reproducibly throws AcquireSqlConnectionFromPool NullReference on the first API GET after tenant reset: uptake IS Integration job111493435528 (CapabilitiesProjectsEnabledViaAPI) and full MX Default job111493443618 (TestGetCurrencyExchangeRates). Both occur56–64 seconds after tenant3 reset; later independent requests pass, but the failed methods do not recover. No scheduler reset/worker overlap was found. Async runtime/pool lifecycle coupling remains possible, unproven—not infrastructure-only. Exact implementation is unavailable in the exposed NAV tree; runtime-owner source/PDB analysis of pool lifetime across dismount/copy/remount is required. Separately, uptake-validation BE job111494278233 fails ordinary SLS installation with a duplicate datasearch sequence before clean execution. Runner/network outages are separate failures. No AL retries, arbitrary waits or classifier broadening will mask these failures.

Verified partial evidence: direct uptake CU148343 passes 153/198 cases across17 countries, including all9 methods and the repaired policy snapshot method. CA/CZ/ES/NL/NO artifacts were missing at2026-10-04T19:58Z; absence is not failure or success. Original8 methods, all assertions, four response clears and five query-safe URLs are preserved alongside upstream's ninth method. Local Pester remains117/117 at workflow/uptake/full. All4 exact-head PowerShell runs passed; workflow-validation37215974877 required attempt2 after one analyzer-tool crash; the other3 passed attempt1. Uptake PowerShell provenance is validation37215973669 at the same uptake SHA, not a separate direct-branch run.

The supported finalizer ran after normal teardown in direct workflow BE Default job111495104917 at2026-10-04T19:30:13.2943924Z and direct uptake DE Integration job111493433096 at2026-10-04T19:37:30.6075547Z. These markers prove hook invocation, not explicit deletion when teardown already removed the file. The23 committed wrappers/shared finalizer and absent generator remain unchanged. Accepted limitation: explicit cleanup is success-only; failed/cancelled runs rely on normal container teardown, with no hard-runner-loss guarantee. Credential ACL protections remain; per-run disposable CI credentials limit risk, not eliminate it.

No CU139496 runtime evidence yet; Legacy1 remains unverified and W1 Default does not cover it. Windows authentication, excluded CompanyInfo (TestGetCompanyAndEnvironmentDescriptions, PR11741), Travel, PDF/native coverage remain unverified/excluded as applicable. Existing review fixes/resolutions, native stack #11893, merged prefix, approval/queue/draft states and upstream exclusions remain unchanged. Permission cleanup from PR11561 is retained. No new source change, baseline update, push, merge or AL retry accompanies this checkpoint. Validation drafts remain Do Not Merge.

@github-actions github-actions Bot added Build: Automation Workflows and other setup in .github folder Build: scripts & configs Build scripts and configuration files labels Sep 25, 2026
@t-prda
Prangshuman Das (t-prda) added this pull request to stack #11893 September 25, 2026 08:47
@github-actions github-actions Bot added Ownership: Needs Review Ownership is Other, low confidence, or needs manual correction Team: Other GitHub request for other area than SCM, Finance or Integration labels Sep 25, 2026
@github-actions github-actions Bot added this to the Version 30.0 milestone Sep 25, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Issue #11561 is not valid. Please make sure you link an issue that exists, is open and is approved.

@t-prda
Prangshuman Das (t-prda) marked this pull request as ready for review September 28, 2026 10:39
@t-prda
Prangshuman Das (t-prda) requested a review from a team September 28, 2026 10:39
Base automatically changed from features/646383-api-test-prerequisites to main September 29, 2026 18:43
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
The historical workflow patch relocated the original core checks. Remove that duplicate while retaining the behavioral workflow tests and downstream AL adoption metadata assertions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
@t-prda
Prangshuman Das (t-prda) force-pushed the features/646383-api-test-workflow branch from 9269e3d to 6e1d8bb Compare September 29, 2026 18:43
pull Bot pushed a commit to CarstenMertes/BCApps that referenced this pull request Sep 29, 2026
## Purpose


[AB#646383](https://dynamicssmb2.visualstudio.com/Dynamics%20SMB/_workitems/edit/646383)

Add opt-in authentication to `Library - Graph Mgt.` without API
re-enablement or pipeline changes.

## Design

- Default `None` preserves existing behavior. The public enum/interface
and public `API Test Auth Context` retain external provider
extensibility.
- The Microsoft provider stays `Internal`; context `Apply` stays
internal. Internal visibility is API encapsulation, not authorization.
- Credential precedence remains container file, then existing Key Vault
only if the file is absent. Invalid configured credentials fail;
successful passwords remain instance-scoped `SecretText`.
- File credentials now use a private file-mapping provider directly,
without replacing or clearing the session-wide Azure Key Vault
provider/cache. No extra AL plaintext copy is introduced.
- `OnAfterInitializeWebRequestWithURL` remains last. The pre-existing
empty Graph `OnRun` is restored.

The trust boundary is admitted OnPrem test code and environment
credential access, not `Internal` visibility or a destination-URL
restriction.

## Tests and scope

All six AL contracts remain: default None, event ordering, provider
reuse, instance scoping, same-provider reselection and deselection.
The dedicated recorder is removed. The non-SingleInstance internal mock
publishes the **test-only** `OnAfterConfigureAuthentication` event; the
same manually bound test-codeunit instance owns `Library - Variable
Storage` for both recording and verification. Initialization clears that
instance's queue after prior failures; each contract drains it and calls
`AssertEmpty`.

The six source-pattern PowerShell checks are removed, not replaced by
other AL-text assertions. The real 401/200/401 HTTP scenario is owned by
uptake microsoft#11860 after credential provisioning; core has no dependency on
that future workflow. This is not a claim of a complete provider-branch
matrix.

No caller migration, URL repair, credential provisioning, scheduling,
exclusion or work-date rollout belongs to this core.

Native stack #11893: **microsoft#10085 auth core -> microsoft#11862 URL/fixture
prerequisites -> microsoft#11891 workflow infrastructure -> microsoft#11860 AL uptake ->
microsoft#11224–microsoft#11230 -> microsoft#11322 -> microsoft#11451–microsoft#11454**.

## Current checkpoint

Head `4a76bb71851c158083dbe4d22e84bf40a0577842`, tree
`12739039e502a3feeea9e98694fb360ea959c606`.

Merged main baseline remains `0a602a2481c93ebfe7b1d27d6016fb9926c42111`
(permission cleanup from PR 11561). No additional main merge or code
changes were made during finalization. Old `b195c7a`/`4eef8ac`
tree-equality claims remain obsolete after the intentional baseline/auth
changes.

[Verified AL compile/publish/test run
36131334134](https://github.com/microsoft/BCApps/actions/runs/36131334134)
**succeeded, attempt 2**, at exact validation head
`4a76bb71851c158083dbe4d22e84bf40a0577842`. **113/113 test jobs and
113/113 cleanup steps succeeded.** Core has no credential-file
provisioning/removal step (expected).

W1 artifacts verify all **6 auth contracts**.

Local Pester at the applicable checkpoint: **28 passed, zero
failed/skipped**. Core local Pester: **28 passed**; no unsupported claim
about a separate root PowerShell workflow.

## Validation limits

For uptake/full, CU139496
`MicrosoftAuthenticationRespectsServerAuthMode` is verified in the
actual UserPassword fixture (**401/200/401**). The Windows
**200/200/200** expectations are implemented but **Windows runtime
remains unverified**; no foreign local NST was used. Successful GitHub
runs do not establish universal native NAV coverage. Excluded PDF cases,
country-specific absent/excluded cases and tolerated-native distinctions
are not claimed passing. No PR has been merged or auto-merged;
validation drafts remain Do Not Merge outside stack #11893.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
pull Bot pushed a commit to CarstenMertes/BCApps that referenced this pull request Sep 29, 2026
## Scope


[AB#646383](https://dynamicssmb2.visualstudio.com/Dynamics%20SMB/_workitems/edit/646383)

Prerequisite layer above microsoft#10085. Move existing **non-authentication**
repairs out of the auth-only base so reviewers can assess them
separately.

- Query-safe Graph URL path/query helpers and
`CreateTargetURLWithTwoSubpages`, with five existing URL regressions.
- Corresponding URL composition changes in API callers.
- Existing APIV2 RapidStart fixture/polling, journal-handler and
Foundation-setup corrections.
- Existing Expense Activity/Policy API fixture and assertion
corrections.
- Existing Czech inventory-posting fixture corrections, also tracked by
microsoft#11370.
- Three existing fixture-variable relocations, retained without claiming
separate product bugs.

No provider-adoption calls, work-date rollout, `RequiredTestIsolation`
changes, pipeline configuration or exclusion changes belong to this
layer. The old Expense auth helper and bindings remain until uptake.

## Dependency and validation

This PR remains the separate 18-file prerequisite above microsoft#10085; its
owned patch is unchanged by the main refresh. The five URL tests remain
alongside the six core contracts in CU139494 (11 methods). Workflow
microsoft#11891 follows it without changing AL source; AL adoption remains
microsoft#11860. No exclusions or pipeline files change here.

The root core's queue/KV fixes are inherited, not duplicated. Standalone
feature-base checks are distinct from main-targeted workflow/uptake/full
validation; none of the previous successful cumulative runs is new-head
proof.

## Current checkpoint

Head `768a6395f186f4db4981631dbcacaa01677c5d40`, tree
`0bea3b816388c79fb950a8ad22bb11ff0f2598be`.

Merged main baseline remains `0a602a2481c93ebfe7b1d27d6016fb9926c42111`
(permission cleanup from PR 11561). No additional main merge or code
changes were made during finalization. Old `b195c7a`/`4eef8ac`
tree-equality claims remain obsolete after the intentional baseline/auth
changes.

[Verified AL compile/publish/test run
36157073629](https://github.com/microsoft/BCApps/actions/runs/36157073629)
**succeeded, attempt 1**, at exact validation head
`9269e3df582704881a898e19029308e9296cbbf1`. **113/113 test jobs and
113/113 cleanup steps succeeded.** **113/113 credential-removal steps**
also succeeded.

W1 artifacts verify all **11 auth/URL methods**. Clean-codeunit
activation remains absent/off; ordinary execution, Legacy and the Unit
Disabled fallback are preserved. This prerequisite is validated as part
of the successful workflow cumulative head, not by a claimed standalone
prerequisite run.

Local Pester at the applicable checkpoint: **28 passed, zero
failed/skipped**. [PowerShell run
36157073348](https://github.com/microsoft/BCApps/actions/runs/36157073348)
**succeeded, attempt 1**.

## Validation limits

For uptake/full, CU139496
`MicrosoftAuthenticationRespectsServerAuthMode` is verified in the
actual UserPassword fixture (**401/200/401**). The Windows
**200/200/200** expectations are implemented but **Windows runtime
remains unverified**; no foreign local NST was used. Successful GitHub
runs do not establish universal native NAV coverage. Excluded PDF cases,
country-specific absent/excluded cases and tolerated-native distinctions
are not claimed passing. No PR has been merged or auto-merged;
validation drafts remain Do Not Merge outside stack #11893.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Comment thread .github/workflows/_BuildALGoProject.yaml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The overly broad transient-failure signature can retry and mask genuine intermittent API regressions.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds workflow infrastructure for securely provisioning API test credentials and opt-in clean-tenant execution of Disabled-isolation codeunits.

Changes:

  • Materializes and securely removes container credentials.
  • Adds clean-tenant discovery, reset, scheduling, retry, and result aggregation.
  • Adds extensive PowerShell and ACL coverage while leaving clean execution disabled by default.
File Description
.github/​AL-Go-Settings.json Enables Task Scheduler only for Uncategorized tests.
.github/​workflows/​_BuildALGoProject.yaml Adds unconditional credential cleanup.
build/​scripts/​ApiTestCredential.psm1 Securely creates the credential file.
build/​scripts/​NewBcContainer.ps1 Provisions credentials for password-authenticated containers.
build/​scripts/​ParallelTestExecution.psm1 Implements clean-tenant scheduling and retries.
build/​scripts/​Remove-ApiTestPassword.ps1 Stops consumers and deletes credentials.
build/​scripts/​RunTestsInBcContainer.ps1 Integrates clean execution and transient detection.
build/​scripts/​tests/​ApiTestCredential.Test.ps1 Tests credential materialization and ACLs.
build/​scripts/​tests/​ParallelTestExecution.Test.ps1 Tests scheduling, restoration, retries, and merging.
build/​scripts/​tests/​Remove-ApiTestPassword.Test.ps1 Tests credential cleanup and workflow lifetime.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread build/scripts/ParallelTestExecution.psm1 Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Remove the wrapper generator and its generator-specific tests. Keep the shared finalizer and behavioral tests that execute every project wrapper.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Comment thread build/scripts/ParallelTestExecution.psm1 Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91

This branch was successfully deployed

1 active (outdated) deployment
triage — 9269e3df Deployed Sep 29, 2026 by t-prda via Classify team ownership #6220
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Build: Automation Workflows and other setup in .github folder Build: scripts & configs Build scripts and configuration files Ownership: Needs Review Ownership is Other, low confidence, or needs manual correction Team: Other GitHub request for other area than SCM, Finance or Integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants