Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
202 commits
Select commit Hold shift + click to select a range
870b4f4
Fix API test authentication in BCApps
t-prda Aug 10, 2026
dedb354
Clarify credential file path parameter
t-prda Aug 10, 2026
16f3424
Avoid sensitive parameter name false positive
t-prda Aug 10, 2026
2ec8094
Scope API test authentication explicitly
t-prda Aug 11, 2026
0193a4f
Place Graph auth bindings after test properties
t-prda Aug 11, 2026
41fbc83
Fix E-Document Graph auth trigger placement
t-prda Aug 11, 2026
11c5ec5
Declare Graph library for E-Document test binding
t-prda Aug 11, 2026
3e3eacb
Resolve W1 warning failures
t-prda Aug 11, 2026
44b1d30
Propagate prepayment warning suppression
t-prda Aug 11, 2026
e2cdd65
Qualify Graph auth helper namespace
t-prda Aug 11, 2026
ed5f78c
Import Graph auth helper dependencies
t-prda Aug 11, 2026
c025edb
Scope Graph password file check to OnPrem
t-prda Aug 11, 2026
7488f41
Import System dotnet aliases for Graph auth
t-prda Aug 11, 2026
5e670d6
Remove unused Graph auth namespace import
t-prda Aug 11, 2026
a412589
Address API auth review findings
t-prda Aug 11, 2026
aacaea5
Fix resumed PR validation failures
t-prda Aug 12, 2026
f63a482
Keep build optimization baseline unchanged
t-prda Aug 12, 2026
0e9f2da
Update E-Document dependency count
t-prda Aug 12, 2026
624b437
Restore E-Document Graph helper variable
t-prda Aug 12, 2026
1aa001d
Narrow API test re-enablement
t-prda Aug 12, 2026
6677c1e
Run Expense API tests with disabled isolation
t-prda Aug 12, 2026
fac14d9
Revert "Run Expense API tests with disabled isolation"
t-prda Aug 13, 2026
16b5b9e
Enable Expense Agent API integration tests
t-prda Aug 13, 2026
89f8d6b
Keep stateful capability API tests disabled
t-prda Aug 13, 2026
9b063ea
Temporarily limit PR validation to W1
t-prda Aug 13, 2026
5131fb6
Fix temporary W1 project paths
t-prda Aug 13, 2026
ad2b38e
Make capability API assertions row-specific
t-prda Aug 13, 2026
d88a833
Use baseline artifacts for W1-only validation
t-prda Aug 13, 2026
74b131b
Benchmark test tenant refresh
t-prda Aug 14, 2026
77997bb
Fix tenant refresh benchmark cleanup
t-prda Aug 14, 2026
c60eb68
Remove temporary tenant refresh benchmark
t-prda Aug 14, 2026
59fc283
Run disabled-isolation tests on clean tenants
t-prda Aug 14, 2026
d809629
Enable APIV2 disabled-isolation tests
t-prda Aug 14, 2026
26ef27f
Stub test discovery in PowerShell tests
t-prda Aug 14, 2026
ed3be0c
Run all APIV1 and APIV2 tests with disabled isolation
t-prda Aug 14, 2026
3d3a6c1
Preauthenticate Graph API test requests
t-prda Aug 14, 2026
e9e26c3
Fix APIV2 test dates for CI license
t-prda Aug 14, 2026
0cebd0e
Reuse APIV2 sales credit memo ERM library
t-prda Aug 14, 2026
b09233c
Scope clean tenant tests to configured apps
t-prda Aug 15, 2026
a180779
Initialize API test work dates consistently
t-prda Aug 15, 2026
27bdffe
Fix purchase return shipment PDF report selection
t-prda Aug 15, 2026
e393e10
Fix isolated API test assertions
t-prda Aug 15, 2026
de891a8
Fix Automation RS Package clean runs
t-prda Aug 15, 2026
2f478c8
Match APIV2 enablement to NAV web service bucket
t-prda Aug 15, 2026
7f86625
Match all NAV API execution paths
t-prda Aug 15, 2026
3612c1f
Validate clean tenants for required-isolation apps
t-prda Aug 15, 2026
33c3f62
Build multitenant-safe API test URLs
t-prda Aug 15, 2026
f95a1c6
Use a license-safe API test work date
t-prda Aug 15, 2026
8dabd83
Enable scheduler for clean API tests
t-prda Aug 15, 2026
54d8180
Build nested API paths before tenant queries
t-prda Aug 15, 2026
9c6b299
Remove unused API test library variable
t-prda Aug 15, 2026
f4f819b
Fix final API test record matching
t-prda Aug 16, 2026
4ede6a1
Match APIV1 lines by composite identifiers
t-prda Aug 16, 2026
7c32c28
Identify created APIV1 lines by description
t-prda Aug 16, 2026
c005c68
Use GUID descriptions for APIV1 line tests
t-prda Aug 16, 2026
27f60fb
Scan document lines for APIV1 test records
t-prda Aug 16, 2026
c4eaac1
Reserve default tenant during clean test runs
t-prda Aug 16, 2026
d0114f5
Keep quality management integration ordering
t-prda Aug 16, 2026
a319973
Restore normal pull request validation
t-prda Aug 17, 2026
e5df951
Pin clean test retries to tenant results
t-prda Aug 17, 2026
04a6a7e
Use localized-safe API test setup
t-prda Aug 17, 2026
38cff89
Initialize localized API posting setup
t-prda Aug 17, 2026
a65ab83
Satisfy API test library analyzer
t-prda Aug 17, 2026
128cc1a
Stabilize localized API test setup
t-prda Aug 17, 2026
3cad877
Reuse graph journal test library variable
t-prda Aug 17, 2026
a8646da
Trigger API test validation
t-prda Aug 17, 2026
9c5c023
Merge remote-tracking branch 'origin/main' into prdas/646383-api-test…
t-prda Aug 17, 2026
1d98cc5
Merge latest main into API test branch
t-prda Aug 17, 2026
5036be5
Migrate new expense activity API tests
t-prda Aug 17, 2026
fed7972
Create exact localized VAT setup keys
t-prda Aug 17, 2026
74af994
Initialize localized API line setup
t-prda Aug 18, 2026
691ee7c
Initialize API item charge posting setup
t-prda Aug 18, 2026
962693f
Merge current API test exclusions
t-prda Aug 18, 2026
37dc3cf
Stabilize remaining API test setup
t-prda Aug 18, 2026
5513615
Run expense API tests on clean tenants
t-prda Aug 18, 2026
6d38d5b
Exclude clean codeunits from normal test passes
t-prda Aug 19, 2026
6a42664
Rebind activity API test authentication
t-prda Aug 19, 2026
1a26ef4
Restore cleared API auth subscriptions
t-prda Aug 19, 2026
5811206
Merge latest scheduler warmup changes
t-prda Aug 19, 2026
10dfcdf
Bind activity API auth after cleanup
t-prda Aug 19, 2026
e0f0fe4
Refresh API auth before each request
t-prda Aug 19, 2026
4e9af97
Apply API authentication directly
t-prda Aug 19, 2026
5cde7a2
Persist shared API authentication state
t-prda Aug 20, 2026
399810e
Apply environment-aware Graph authentication
t-prda Aug 20, 2026
0fdaea9
Build tenant-safe activity API URLs
t-prda Aug 20, 2026
b4d6ba6
Disable regressed expense capability API test
t-prda Aug 20, 2026
f033391
Scope disabled tests by country
t-prda Aug 21, 2026
c627dfb
Track second India capability regression
t-prda Aug 21, 2026
ec8404a
Address API test review comments
t-prda Aug 21, 2026
5fd8861
Document parallel test helpers
t-prda Aug 21, 2026
3340b9f
Scope India capability cold-start exclusion
t-prda Aug 21, 2026
8c22364
Remove obsolete API initialization state
t-prda Aug 21, 2026
b6c33c9
Merge latest test rerun infrastructure
t-prda Aug 21, 2026
4775979
Migrate new expense policy API tests
t-prda Aug 21, 2026
3955c2e
Fix newly enabled expense API tests
t-prda Aug 21, 2026
4ee01ad
Load activity event type for API records
t-prda Aug 22, 2026
3d08c14
Initialize activity API currency setup
t-prda Aug 22, 2026
aae2e00
Load activity fields before API trigger logic
t-prda Aug 22, 2026
6cc8c30
Create valid submitted activity fixture
t-prda Aug 22, 2026
48eb1d5
Unify clean and app retry state handling
t-prda Aug 22, 2026
79fa9b6
Enable Task Scheduler before test execution
t-prda Aug 23, 2026
7f83dd9
Address final API test review findings
t-prda Aug 25, 2026
556ec6f
Migrate remaining Graph auth caller
t-prda Aug 25, 2026
3b9bc36
Create reason codes for invoice cancellation tests
t-prda Aug 25, 2026
90d2f99
Update E-Document dependency count
t-prda Aug 25, 2026
450f5b2
Retry transient clean tenant database copies
t-prda Aug 25, 2026
1938bb2
Use docker exec for clean tenant database copies
t-prda Aug 26, 2026
0dc3ec8
Stub container script command in scheduler tests
t-prda Aug 26, 2026
e835162
Retry source tenant resolution for clean templates
t-prda Aug 26, 2026
f8fc045
Reuse known database name for clean template
t-prda Aug 26, 2026
31a0526
Isolate task scheduler to clean test phase
t-prda Aug 26, 2026
d220a68
Restore clean tenants before normal tests
t-prda Aug 26, 2026
d3ff48d
Clarify background job variable scope
t-prda Aug 26, 2026
2811a3e
Merge main into API test auth branch
t-prda Aug 26, 2026
874c98a
Retrigger validation after main merge
t-prda Aug 26, 2026
fdfb2e1
Retrigger validation after Actions recovery
t-prda Aug 26, 2026
51ba60b
Merge 30.0 obsolete-tag fixes from main
t-prda Aug 27, 2026
43fb2db
Retry test metadata selection races
t-prda Aug 27, 2026
89f74e8
Serialize clean tenant database resets
t-prda Aug 27, 2026
16a4e42
Propagate test metadata race markers
t-prda Aug 27, 2026
ae60ea9
Batch clean tenant restores before tests
t-prda Aug 27, 2026
7e6cb40
Retry clean API cold-start failures
t-prda Aug 28, 2026
3ada2aa
Address final automated review findings
t-prda Aug 28, 2026
6dcc9b6
Scope API test auth to current service
t-prda Aug 28, 2026
19c741b
Address latest automated review findings
t-prda Aug 28, 2026
8007e4e
Cache API auth outside request events
t-prda Aug 28, 2026
4008dc4
Retrigger final validation
t-prda Aug 28, 2026
8af221f
Merge latest main into API test auth branch
t-prda Aug 28, 2026
0253fc0
Set license-safe date for assembly API tests
t-prda Aug 28, 2026
700977d
Make API test authentication extensible
t-prda Aug 31, 2026
cb8753a
Merge latest main into API test auth branch
t-prda Aug 31, 2026
65414f7
Remove stale API auth import
t-prda Aug 31, 2026
68fa7ff
Fix API auth provider compilation
t-prda Aug 31, 2026
ae2cb7e
Align API auth interface syntax
t-prda Aug 31, 2026
69c4289
Remove invalid global using directive
t-prda Aug 31, 2026
f817ae3
Fix API auth test compilation
t-prda Aug 31, 2026
0904cab
Suppress legacy namespace warnings
t-prda Aug 31, 2026
a6fac87
Validate API authentication scheme
t-prda Aug 31, 2026
6846d5c
Discover Disabled-isolation tests without an app allowlist
t-prda Sep 7, 2026
04028c1
Remove unused country-specific test exclusions
t-prda Sep 7, 2026
47551e7
Enable all Expense Agent test methods for parity validation
t-prda Sep 7, 2026
921e890
Keep unrelated Expense Agent failures out of scope
t-prda Sep 7, 2026
c988cd4
Simplify API authentication and initialize providers per test instance
t-prda Sep 8, 2026
f47888c
Register Dimension Lines initialization regression during test discovery
t-prda Sep 8, 2026
2a553ac
Avoid event-parameter shadowing in API provider tests
t-prda Sep 8, 2026
6cd9bf1
Bound clean discovery and close API credential lifetime
t-prda Sep 9, 2026
65d56fb
Use platform-neutral paths in credential cleanup tests
t-prda Sep 9, 2026
396c38c
Refresh API auth branch while preserving deferred Expense tests
t-prda Sep 10, 2026
1916826
Initialize auth once and reapply license-safe dates before fixtures
t-prda Sep 10, 2026
a4ed3c3
Fix Travel Request action-result assertions for runtime compilation
t-prda Sep 10, 2026
2028f76
Bring in independently reviewed Travel Request compilation prerequisite
t-prda Sep 10, 2026
86497ab
Compare formatted web service action results using the supported intr…
t-prda Sep 10, 2026
b05ed58
Refresh the independently reviewable action-result prerequisite
t-prda Sep 10, 2026
6d1663c
Preserve fixture state and configured task scheduling during clean tests
t-prda Sep 11, 2026
06308e1
Enable background tasks explicitly for Uncategorized API tests
t-prda Sep 11, 2026
9b196da
Make Czech advance-payment posting fixtures self-contained
t-prda Sep 11, 2026
b85fcfb
Include the separately reviewable Czech fixture prerequisite
t-prda Sep 11, 2026
25916ae
Avoid shadowing the automatic PROFILE variable in profile tests
t-prda Sep 11, 2026
8d55682
Merge latest main before reassessing Expense test failures
t-prda Sep 14, 2026
76d18ba
Temporarily defer confirmed Expense failures for dedicated stacked fixes
t-prda Sep 14, 2026
fd79dbd
Merge latest main and preserve scoped Expense test deferrals
t-prda Sep 15, 2026
4c4b30f
Address API authentication and test-runner review feedback
t-prda Sep 15, 2026
59c60a4
Use the declared web-service option type in URL test fixtures
t-prda Sep 15, 2026
2f1a5d9
Keep work-date fixes limited to the agreed failure scope
t-prda Sep 15, 2026
f516524
Avoid immutable plaintext copies in API credential materialization
t-prda Sep 15, 2026
ae9265e
Merge current main and reconcile Expense test deferrals
t-prda Sep 18, 2026
86ae50b
Construct synthetic credentials without the plaintext conversion flag
t-prda Sep 21, 2026
9eede3e
Remove empty triggers and misleading AI-test feature labels
t-prda Sep 24, 2026
303c0bf
Separate authentication core from pipeline and API uptake
t-prda Sep 24, 2026
45d8343
Separate API URL and fixture prerequisites from authentication
t-prda Sep 24, 2026
027bfcc
Separate API test workflow infrastructure from AL uptake
t-prda Sep 25, 2026
9e9365c
Use test-owned auth recording and isolate container credential lookup
t-prda Sep 25, 2026
595eda2
Merge current main baseline into the API auth core
t-prda Sep 25, 2026
e357a1c
Refresh api-prerequisites layer with the reviewed auth base
t-prda Sep 25, 2026
924c791
Refresh api-workflow layer with the reviewed auth base
t-prda Sep 25, 2026
e5dbba4
Remove relocated auth source-pattern checks from workflow tests
t-prda Sep 25, 2026
e766fc8
Name the mock auth event after its publisher position
t-prda Sep 25, 2026
ccb1529
Refresh api-prerequisites layer with the reviewed auth base
t-prda Sep 25, 2026
116ad30
Refresh api-workflow layer with the reviewed auth base
t-prda Sep 25, 2026
01dc1b9
Import test-library DotNet alias for private auth credential reader
t-prda Sep 25, 2026
23e03c1
Refresh api-prerequisites layer with the reviewed auth base
t-prda Sep 25, 2026
8d9a0c0
Refresh api-workflow layer with the reviewed auth base
t-prda Sep 25, 2026
4a76bb7
Restore typed conversion for mock authentication credential
t-prda Sep 25, 2026
768a639
Refresh api-prerequisites layer with the reviewed auth base
t-prda Sep 25, 2026
d3601b0
Refresh api-workflow layer with the reviewed auth base
t-prda Sep 25, 2026
9269e3d
Keep clean-codeunit lanes opt-in until authentication uptake
t-prda Sep 25, 2026
7a0b32d
Separate API test workflow infrastructure from AL uptake
t-prda Sep 25, 2026
564bc06
Remove relocated auth source-pattern checks from workflow tests
t-prda Sep 25, 2026
6e1d8bb
Keep clean-codeunit lanes opt-in until authentication uptake
t-prda Sep 25, 2026
1d81466
Merge current main baseline while preserving scoped API test exclusions
t-prda Sep 30, 2026
779308e
Forward-merge current workflow into historical validation branch
t-prda Sep 30, 2026
156bca0
Do not classify ordinary API HTTP500 failures as platform races
t-prda Oct 2, 2026
1aa56d4
Forward-merge classifier fix into workflow validation
t-prda Oct 2, 2026
decc121
Do not classify ordinary API HTTP500 failures as platform races
t-prda Oct 2, 2026
52621da
Forward-merge classifier fix into workflow validation
t-prda Oct 2, 2026
a439380
Move API test credential cleanup to supported PipelineFinalize hook
t-prda Oct 2, 2026
d40ed18
Forward-merge credential finalizer into workflow validation
t-prda Oct 2, 2026
dd6207b
Simplify finalizer maintenance by retaining committed wrappers
t-prda Oct 2, 2026
331ae4b
Merge current main with simplified supported API credential finalizer
t-prda Oct 2, 2026
e89e906
Forward-merge simplified finalizer and current baseline into workflow…
t-prda Oct 2, 2026
dcc0733
Merge main baseline containing upstream CLEAN27 warning cleanup
t-prda Oct 2, 2026
8e4ad69
Forward-merge captured warning baseline into workflow validation
t-prda Oct 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/AL-Go-Settings.json
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,14 @@
]
}
},
{
"buildModes": [
"UncategorizedTests"
],
"settings": {
"enableTaskScheduler": true
}
},
{
"buildModes": [
"LegacyTestsBucket1"
Expand Down
1 change: 1 addition & 0 deletions build/projects/Test Apps AT/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps AU/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps BE/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps CA/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps CH/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps CZ/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps DE/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps DK/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps ES/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps FI/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps FR/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps GB/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps IN/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps IS/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps IT/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps MX/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps NL/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps NO/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps NZ/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps RU/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps SE/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps US/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
1 change: 1 addition & 0 deletions build/projects/Test Apps W1/.AL-Go/PipelineFinalize.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
. (Join-Path $PSScriptRoot '../../../scripts/PipelineFinalize.ps1' -Resolve)
117 changes: 117 additions & 0 deletions build/scripts/ApiTestCredential.psm1
Original file line number Diff line number Diff line change
@@ -0,0 +1,117 @@
function New-ApiTestPasswordFileStream {
param([Parameter(Mandatory = $true)][string]$FilePath)

$ErrorActionPreference = 'Stop'
$security = [System.Security.AccessControl.FileSecurity]::new()
$security.SetAccessRuleProtection($true, $false)
$writerSid = [System.Security.Principal.WindowsIdentity]::GetCurrent().User.Value
$entries = @(
@{ Sid = 'S-1-5-18'; Rights = [System.Security.AccessControl.FileSystemRights]::FullControl }
@{ Sid = 'S-1-5-20'; Rights = [System.Security.AccessControl.FileSystemRights]::Read }
@{ Sid = 'S-1-5-32-544'; Rights = [System.Security.AccessControl.FileSystemRights]::FullControl }
)
if ($writerSid -notin @('S-1-5-18', 'S-1-5-32-544')) {
# The host identity writes the credential and deletes it during cleanup; it needs
# neither ReadData nor FullControl. Container service identities retain their access.
$entries += @{
Sid = $writerSid
Rights = [System.Security.AccessControl.FileSystemRights]'Write, Delete'
}
}
foreach ($entry in $entries) {
$security.AddAccessRule([System.Security.AccessControl.FileSystemAccessRule]::new(
[System.Security.Principal.SecurityIdentifier]::new($entry.Sid),
$entry.Rights,
[System.Security.AccessControl.AccessControlType]::Allow))
}

# Supply the protected DACL to CreateFile itself, not Set-Acl after creation.
# CreateNew also refuses to follow or overwrite a pre-existing credential file.
if ($PSVersionTable.PSEdition -eq 'Core') {
return [System.IO.FileSystemAclExtensions]::Create(
[System.IO.FileInfo]::new($FilePath), [System.IO.FileMode]::CreateNew,
[System.Security.AccessControl.FileSystemRights]::Write, [System.IO.FileShare]::None,
4096, [System.IO.FileOptions]::None, $security)
}
return [System.IO.FileStream]::new(
$FilePath, [System.IO.FileMode]::CreateNew,
[System.Security.AccessControl.FileSystemRights]::Write, [System.IO.FileShare]::None,
4096, [System.IO.FileOptions]::None, $security)
}

<#
.SYNOPSIS
Creates the API test credential directly in the container's shared my mount.
.DESCRIPTION
Records cleanup identity before atomically creating a new file with a protected
DACL. No plaintext staging copies are made. SYSTEM and Administrators retain full
access, NetworkService can read, and the host writer can write and delete.
An existing file or unresolved mount is an error, including outside CI. Successful
pipelines finalize cleanup; failed/cancelled pipelines rely on container teardown.
#>
function Write-ApiTestPassword {
param(
[Parameter(Mandatory = $true)]
[ValidatePattern('^[a-zA-Z0-9][a-zA-Z0-9_.-]*$')]
[string]$ContainerName,
[Parameter(Mandatory = $true)]
[PSCredential]$Credential
)

$ErrorActionPreference = 'Stop'
$myFolders = @((Get-BcContainerSharedFolders -containerName $ContainerName).GetEnumerator() |
Where-Object { $_.Value.TrimEnd('\') -eq 'C:\Run\my' })
if ($myFolders.Count -ne 1) {
throw "Cannot resolve the API test credential's container mount."
}
$filePath = Join-Path $myFolders[0].Key 'ApiTestPassword'
# PipelineFinalize runs in this process; GITHUB_ENV only affects later steps.
$env:BCAppsApiTestPasswordPath = $filePath
$env:BCAppsApiTestPasswordContainer = $ContainerName
if ($env:GITHUB_ENV) {
Add-Content -LiteralPath $env:GITHUB_ENV -Encoding UTF8 -Value @(
"BCAppsApiTestPasswordPath=$filePath"
"BCAppsApiTestPasswordContainer=$ContainerName"
) -ErrorAction Stop
}

$created = $false
$bytes = $null
$characters = $null
$passwordBuffer = [IntPtr]::Zero
try {
# Write directly to the shared mount. Copy-FileToBcContainer would introduce
# another host staging copy with inherited permissions.
$stream = New-ApiTestPasswordFileStream -FilePath $filePath
$created = $true
try {
$passwordBuffer = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($Credential.Password)
$characters = [char[]]::new($Credential.Password.Length)
[System.Runtime.InteropServices.Marshal]::Copy($passwordBuffer, $characters, 0, $characters.Length)
$bytes = [System.Text.UTF8Encoding]::new($false).GetBytes($characters)
$stream.Write($bytes, 0, $bytes.Length)
}
finally {
if ($null -ne $bytes) { [Array]::Clear($bytes, 0, $bytes.Length) }
if ($null -ne $characters) { [Array]::Clear($characters, 0, $characters.Length) }
if ($passwordBuffer -ne [IntPtr]::Zero) {
[System.Runtime.InteropServices.Marshal]::ZeroFreeBSTR($passwordBuffer)
}
$stream.Dispose()
}
}
catch {
$originalError = $_
if ($created) {
try {
& (Join-Path $PSScriptRoot 'Remove-ApiTestPassword.ps1') -ContainerName $ContainerName -FilePath $filePath
}
catch {
Write-Warning 'Could not clean up the API test credential after setup failed; container teardown is still required.'
}
}
throw $originalError
}
}

Export-ModuleMember -Function Write-ApiTestPassword
9 changes: 9 additions & 0 deletions build/scripts/NewBcContainer.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,15 @@ if ($platformVersion) {

New-BcContainer @parameters

if ($parameters.auth -in @('UserPassword', 'NavUserPassword')) {
if (-not $parameters.credential) {
throw "The BCApps UserPassword test container requires a credential."
}

Import-Module (Join-Path $PSScriptRoot 'ApiTestCredential.psm1') -Force
Write-ApiTestPassword -ContainerName $parameters.ContainerName -Credential $parameters.credential
}

Set-BcContainerServerConfiguration -containerName $parameters.ContainerName -keyName "EnforceUserPathForAlFileOperations" -keyValue "false"
Set-BcContainerServerConfiguration -containerName $parameters.ContainerName -keyName "UsePermissionSetsFromExtensions" -keyValue "true"
Restart-BcContainer -containerName $parameters.ContainerName
Expand Down
Loading
Loading