Skip to content

docs(AC0031): document AccessByPermission as a permission source - #192

Merged
Arthurvdv merged 1 commit into
mainfrom
docs/ac0031-accessbypermission
Sep 27, 2026
Merged

Arthurvdv merged 1 commit into
mainfrom
docs/ac0031-accessbypermission

Conversation

@Arthurvdv

Copy link
Copy Markdown
Member

Documents the object-level AccessByPermission = tabledata property of reports and pages as a permission source for AC0031. The new text covers the Incoming Document example, the rule that only the chars in the mask count, the table X = X and other-table exclusions, and the runtime limitations. AccessByPermission grants nothing at runtime: the mask is OR-evaluated, it only applies under the UI elements removal setting, and the object can still run from code.

Companion to ALCops/Analyzers#567.

🤖 Generated with Claude Code

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Arthurvdv added a commit to ALCops/Analyzers that referenced this pull request Sep 27, 2026
…rage (#567)

AC0031 reported table data access in reports and pages that gate themselves with
`AccessByPermission = tabledata X = <mask>`, asking for a `Permissions` entry the
object does not need. The property hides the object from users who lack the mask,
so an object that declares it is built for users who already hold that permission
themselves. The Base App never pairs it with a `Permissions` entry for the same
table (report 299 "Delete Invoiced Sales Orders" is the canonical shape).

`PermissionResolver.IsCovered` now reads the object-level `AccessByPermission`
property through the same `ObjectPermissionCovers` matcher as `Permissions`:
only `tabledata` targets count, and only the characters in the mask cover, so
`RD` still leaves a `Modify` reported. Both properties bind through the SDK's
shared `BindPermissionPropertyValue`, and the property is registered at object
level only for pages and reports. `EnumProvider.PropertyKind` exposes the new
member. AC0032 is unchanged: the mask is neither a `Permissions` entry nor a
table use, and an entry whose table is only named in the mask is still reported
as unused.

Fixtures cover the issue shape, the report 299 delete shape, a page reading a
table other than its source table, lowercase masks, a mask missing the needed
character, a different table, the `table X = X` execute form, and the AC0032
pairing cases. Rule docs record the design decision and the accepted
limitations (OR mask semantics, code-run bypass, the UI Elements Removal server
setting, element-level properties out of scope).

Docs: ALCops/alcops.dev#192
Closes #312

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Arthurvdv
Arthurvdv merged commit 46357db into main Sep 27, 2026
1 check passed
@Arthurvdv
Arthurvdv deleted the docs/ac0031-accessbypermission branch September 27, 2026 08:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant