docs(AC0031): document AccessByPermission as a permission source - #192
Merged
Merged
Conversation
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Arthurvdv
added a commit
to ALCops/Analyzers
that referenced
this pull request
Sep 27, 2026
…rage (#567) AC0031 reported table data access in reports and pages that gate themselves with `AccessByPermission = tabledata X = <mask>`, asking for a `Permissions` entry the object does not need. The property hides the object from users who lack the mask, so an object that declares it is built for users who already hold that permission themselves. The Base App never pairs it with a `Permissions` entry for the same table (report 299 "Delete Invoiced Sales Orders" is the canonical shape). `PermissionResolver.IsCovered` now reads the object-level `AccessByPermission` property through the same `ObjectPermissionCovers` matcher as `Permissions`: only `tabledata` targets count, and only the characters in the mask cover, so `RD` still leaves a `Modify` reported. Both properties bind through the SDK's shared `BindPermissionPropertyValue`, and the property is registered at object level only for pages and reports. `EnumProvider.PropertyKind` exposes the new member. AC0032 is unchanged: the mask is neither a `Permissions` entry nor a table use, and an entry whose table is only named in the mask is still reported as unused. Fixtures cover the issue shape, the report 299 delete shape, a page reading a table other than its source table, lowercase masks, a mask missing the needed character, a different table, the `table X = X` execute form, and the AC0032 pairing cases. Rule docs record the design decision and the accepted limitations (OR mask semantics, code-run bypass, the UI Elements Removal server setting, element-level properties out of scope). Docs: ALCops/alcops.dev#192 Closes #312 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documents the object-level
AccessByPermission = tabledataproperty of reports and pages as a permission source for AC0031. The new text covers the Incoming Document example, the rule that only the chars in the mask count, thetable X = Xand other-table exclusions, and the runtime limitations.AccessByPermissiongrants nothing at runtime: the mask is OR-evaluated, it only applies under the UI elements removal setting, and the object can still run from code.Companion to ALCops/Analyzers#567.
🤖 Generated with Claude Code