Skip to content

[Validation only - do not merge] Combined API auth and Expense fix stack - #11455

Draft
Prangshuman Das (t-prda) wants to merge 62 commits into
mainfrom
features/646383-expense-stack-validation
Draft

Prangshuman Das (t-prda) wants to merge 62 commits into
mainfrom
features/646383-expense-stack-validation

Conversation

@t-prda

@t-prda Prangshuman Das (t-prda) commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Validation — runtime BLOCKED

Published and locally validated; fresh AL runtime validation is blocked by GitHub-hosted runner acquisition. Pester117/117 passed, zero failed/skipped, separately at the exact Expense/general/full heads. The existing JSON loader verifies193 temporary method-specific selectors at Expense and zero temporary selectors at general/full. All51 Expense API reenables and nine non-API exclusions remain unchanged; general/full cumulative source trees exactly match the pre-stage-fix checkpoint.

Current exact-head run: https://github.com/microsoft/BCApps/actions/runs/37363758819 (head f6c91f21b7fac7942c9d2dcd589a33c1b1b604c7). The bounded2026-10-05T19:57:56Z–19:57:59Z snapshot across the four checkpoint runs found50 cancelled jobs with the same annotation: The job was not acquired by Runner of type hosted even after multiple attempts. Those50 jobs had no assigned runner and executed no steps. No AL unit/integration test jobs had started in that snapshot. Other compilation jobs were active: this is partial hosted-runner availability, not a claimed global outage or a terminal all-green result.

Required next proof: fresh AL execution of all51 Expense API methods and actual suppression of all193 temporary general-stage selectors when runners become available. Historical head88881be evidence—51 methods across13 countries (663 results), all63 touched API methods (819 results), and Activity coverage117/198—is retained separately and does not substitute for this head's runtime validation. General's earlier SQL-pool lifecycle NRE remains a separate unresolved limit; no fixture/classifier/warning workaround or AL retry was added.

Existing runs remain untouched. Do not retry active runs. Parent monitoring schedule46 may stop at this explicit infrastructure blocker; resume bounded review after terminal outcomes/capacity availability, checking exact heads and all new annotations before any separately authorized retry. No Actions cancellation, source/branch update, PR closure, merge, queue or native-stack change is part of this metadata checkpoint.

Expense-first sequencing using existing exclusions

The same 193 method-specific temporary exclusions (135 APIV1 +58 APIV2 across12 codeunits) now live in the existing src/DisabledTests/_Exclude_APIV1__Tests/_Exclude_APIV1__Tests.DisabledTest.json and src/DisabledTests/_Exclude_APIV2__Tests/_Exclude_APIV2__Tests.DisabledTest.json. No separate sequencing files remain. Original entries retain their order/style/content; no new duplicate or wildcard/codeunit-wide exclusion is introduced. Unrelated pre-existing APIV2 duplicates are preserved rather than mixed with this change.

#11860 removes the temporary additions from these same existing manifests alongside its already-reviewed authentication uptake. All193 temporary stage entries are removed in #11860, but it makes 192/193 target methods eligible: the independent 139739::TestDeleteInUse exclusion remains until the VAT fixture fix #11224 removes it. From #11224 onward all193 are eligible; eligibility is not runtime success. All general/downstream cumulative trees are exactly byte-identical to the preceding checkpoint; the full checkpoint has none of these193 methods excluded. No app-name allowlist, selection setting, runner/authentication/test/production change or Logiq exclusion is added.

Why these methods started executing: they already required Disabled isolation and were IntegrationTest codeunits. Ordinary typed selection in TestSuiteMgt332–352 selects None|Codeunit; the old extra Disabled pass in RunTestsInBcContainer was UnitTest-only. The clean-execution switch newly reaches Disabled IntegrationTest codeunits and still honors the existing JSON exclusions. These193 methods were not listed in those exclusions. This is a pre-existing selection gap, not a newly introduced product auth bug or proof they never ran in any historical configuration. A complete67-codeunit audit preserves existing UnitTest/Legacy behavior and the ten independently handled Logiq integration tests.

**Expense scope is unchanged:**51 API reenables, nine non-API exclusions, baseline six cases and all consolidated regressions. The two legacy Spend Requests methods remain conditional on not CLEAN30. Focused #12325 review:21 files, including the two existing exclusion manifests. General #11860 review:159 files.

The official NAV Disable-NAVALTest helper was inspected: it has no destination/app-file parameter, writes NAV's App/DisabledTests using per-codeunit filenames and sorts entries. It cannot safely preserve these BCApps files. A bounded JSON relocation preserved original prefixes/order and checked exact identities, then exercised the unchanged real loader. No new shared helper/framework or NAV selector change was made.

Validation and presentation evidence

Pester117/117 passed independently at the new Expense/general/full heads. Actual existing-loader checks confirm identical effective193-method selection after relocation and preserved51/9 Expense scope. All nine downstream Git tree hashes remain exactly unchanged. Fresh exact-head CI is pending; old-head successes are not substituted for current runtime evidence.

Historical run37330893173 at head88881be reached193 general methods:171 genuine401 failures and22 nominal passes (17 bare-ASSERTERROR cases can accept the wrong error; five local fixtures). Separately, all51 Expense methods passed in13 inspected countries (663 results), and all63 touched API methods yielded819 results; Activity coverage was117/198 at that checkpoint. These are bounded historical results, not a full/current matrix pass. The preceding stage-fix runs hit50 hosted-runner acquisition cancellations; other jobs were active, so this was not a claimed global outage. New pushes schedule fresh CI, not an AL retry. The general SQL-pool NRE and missing warning-reference artifacts remain separate unresolved limitations.

Durable session presentation notes: api-test-enablement-presentation-notes.md, with source-pinned selection proof, fix/coverage inventory, helper limitations and historical-vs-current evidence boundaries. Fresh runtime proof must still establish the51 Expense cases and actual193-case suppression at Expense stage.

AB#646383 (link only). Native stack #12327 remains #12325 → #11860 → #11224 → #11225 → #11226 → #11227 → #11228 → #11229 → #11230 → #11322. Protected merged #10085/#11862/#11891 and validation #11892 are untouched; validation-only #11861/#11455 remain Do Not Merge. No new main integration, native-group/base change, PR merge, queue operation, Actions cancellation or manual retry was made. All prior heads remain ancestors; source publication used backups and an atomic forward-only push with explicit leases.

Exact current head: f6c91f21b7fac7942c9d2dcd589a33c1b1b604c7; source tree: 8ca40512ed7bab9f5de092df1a16a012fed903fe.

@github-actions github-actions Bot added Build: Automation Workflows and other setup in .github folder Build: scripts & configs Build scripts and configuration files AL: Apps (W1) Add-on apps for W1 Ownership: Needs Review Ownership is Other, low confidence, or needs manual correction Team: Other GitHub request for other area than SCM, Finance or Integration labels Sep 14, 2026
@github-actions github-actions Bot added this to the Version 30.0 milestone Sep 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Issue #11561 is not valid. Please make sure you link an issue that exists, is open and is approved.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
@github-actions github-actions Bot removed the Build: scripts & configs Build scripts and configuration files label Oct 5, 2026
Prangshuman Das (t-prda) and others added 20 commits October 5, 2026 21:18
Temporarily sequence193 existing methods through DisabledTests selectors:135 APIV1 and58 APIV2. Removed in#11860; no product quarantine or selection logic.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Remove the193 temporary Expense-stage selectors. Preserve the complete general uptake source tree exactly.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Relocate the same193 temporary method exclusions without changing selection, authentication or tests. Preserve existing manifest order and remove separate stage files.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Inherit Expense-first manifest relocation and restore the exact general uptake source tree. Existing general exclusions remain owned by their downstream fixes.

AB#646383

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session:3952f078-a881-4da8-ad96-13b727e48a91
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Issue #11224 is not valid. Please make sure you link an issue that exists, is open and is approved.

melnikbo pushed a commit to melnikbo/BCApps that referenced this pull request Oct 7, 2026
…microsoft#12325)

## Scope

Related authentication and API enablement:
[AB#646383](https://dynamicssmb2.visualstudio.com/Dynamics%20SMB/_workitems/edit/646383)
(link only; this PR does not resolve the umbrella item).

Fixes
[AB#653119](https://dynamicssmb2.visualstudio.com/1fcb79e7-ab07-432a-a3c6-6cf5a88ba4a5/_workitems/edit/653119)

Separate test defect: [653119 - Policy snapshot API URL composition and
response
isolation](https://dynamicssmb2.visualstudio.com/Dynamics%20SMB/_workitems/edit/653119).
This tracks the policy-snapshot test corrections, not production access
permissions or unrelated runtime failures.

Expense-first adoption directly against main after the external squash
merge of workflow microsoft#11891; remaining general APIs follow in microsoft#11860.

- Migrate the 11 reviewed Expense API/helper paths to shared
authentication and remove exactly 51 existing Expense API exclusions.
Preserve exactly nine non-API Expense exclusions; all 19 previously
retained API exclusions are now removed.
- Enable the existing `enableCleanTestCodeunitExecution` boolean. Use
existing DisabledTests selectors throughout discovery, ordinary
execution and clean-codeunit execution/reruns. No app-name allowlist,
new selection setting or runner implementation/test change.
- Include the six-line license-safe WorkDate helper needed by PerDiem,
five query-safe policy URL compositions, four independent response
clears, and the existing unlimited-approval fixture. Preserve all nine
Activity Log tests and upstream assertions.
- Consolidate microsoft#11453's exact assigned-user filter (no cross-table range
compression), true fallback fixture and regressions. Upstream wildcard
quoting alone did not fix the range-gap case.
- Consolidate microsoft#11451's unique denied-approval error/permission capture
and microsoft#11454's existing repeated-delta, missing-header-permission,
Released-status and real deletion-total regressions, including its
internal test-only permission set.
- Do not reintroduce upstream repairs from microsoft#11654 (three permission-role
tests and posted zero-amount fixture), the obsolete date test removed by
microsoft#12074, or the production indirect-Modify change already supplied by
microsoft#11333. microsoft#11452's duplicate deletion helper is absent; existing callers
use the upstream shared helper.
- All seven artificial Expense exclusions introduced by the previous
uptake are absent here and at every general checkpoint. This is not
blanket re-enablement of Expense tests.

This focused review diff has21 paths, using the two existing API
exclusion manifests. No NAV selectors, local NST, BC-ExpenseAgent
changes, unrelated new test scope or production permission changes.

Exact head: `bd3bbc04e13965f967a26eef435bdbf0cbc09ad7`; tree:
`2b8c47b138846f63bd49d47188f54ea7e86c1f24`.

## Expense-first sequencing using existing exclusions

The same **193 method-specific temporary exclusions (135 APIV1 +58 APIV2
across12 codeunits)** now live in the existing
`src/DisabledTests/_Exclude_APIV1__Tests/_Exclude_APIV1__Tests.DisabledTest.json`
and
`src/DisabledTests/_Exclude_APIV2__Tests/_Exclude_APIV2__Tests.DisabledTest.json`.
No separate sequencing files remain. Original entries retain their
order/style/content; no new duplicate or wildcard/codeunit-wide
exclusion is introduced. Unrelated pre-existing APIV2 duplicates are
preserved rather than mixed with this change.

microsoft#11860 removes the temporary additions from these same existing
manifests alongside its already-reviewed authentication uptake. All193
temporary stage entries are removed in microsoft#11860, but it makes **192/193
target methods eligible**: the independent `139739::TestDeleteInUse`
exclusion remains until the VAT fixture correction in PR
[microsoft#11224](microsoft#11224) removes it.
From microsoft#11224 onward all193 are eligible; eligibility is not runtime
success. All general/downstream cumulative trees are **exactly
byte-identical** to the preceding checkpoint; the full checkpoint has
none of these193 methods excluded. No app-name allowlist, selection
setting, runner/authentication/test/production change or Logiq exclusion
is added.

**Why these methods started executing:** they already required Disabled
isolation and were IntegrationTest codeunits. Ordinary typed selection
in TestSuiteMgt332–352 selects None|Codeunit; the old extra Disabled
pass in RunTestsInBcContainer was UnitTest-only. The clean-execution
switch newly reaches Disabled IntegrationTest codeunits and still honors
the existing JSON exclusions. These193 methods were not listed in those
exclusions. This is a pre-existing selection gap, not a newly introduced
product auth bug or proof they never ran in any historical
configuration. A complete67-codeunit audit preserves existing
UnitTest/Legacy behavior and the ten independently handled Logiq
integration tests. Historical baseline run37215976231 at
head69df41756d918a516a3c868ca66f45cbfd320428 independently corroborates
this: zero of the exact193 methods appear across five inspected W1
result artifacts containing37,626 testcases (Integration, both Legacy
buckets, default/unit and Uncategorized). This evidence is limited to
that W1 baseline, not every country or historical run. The completed
alternate-path audit found no other ordinary configured baseline BCApps
lane: APIV1/APIV2 are outside Legacy buckets, Disabled-unit fallback
retains UnitTest filtering, discovery skips test procedures, and
ordinary PR/CI/CD/rerun routes do not bypass those constraints. Manual
or explicitly untyped execution remains possible; no universal
historical or NAV absence is claimed.

**Expense scope is unchanged:**51 API reenables, nine non-API
exclusions, baseline six cases and all consolidated regressions. The two
legacy Spend Requests methods remain conditional on not CLEAN30. Focused
microsoft#12325 review:21 files, including the two existing exclusion manifests.
General microsoft#11860 review:159 files.

The official NAV `Disable-NAVALTest` helper was inspected: it has no
destination/app-file parameter, writes NAV's App/DisabledTests using
per-codeunit filenames and sorts entries. It cannot safely preserve
these BCApps files. A bounded JSON relocation preserved original
prefixes/order and checked exact identities, then exercised the
unchanged real loader. No new shared helper/framework or NAV selector
change was made.

## Validation and presentation evidence

**Pester117/117 passed independently at the new Expense/general/full
heads.** Actual existing-loader checks confirm identical
effective193-method selection after relocation and preserved51/9 Expense
scope. All nine downstream Git tree hashes remain exactly unchanged.
Fresh exact-head CI is pending; old-head successes are not substituted
for current runtime evidence.

Historical run37330893173 at head88881be reached193 general methods:171
genuine401 failures and22 nominal passes (17 bare-ASSERTERROR cases can
accept the wrong error; five local fixtures). Separately, all51 Expense
methods passed in13 inspected countries (663 results), and all63 touched
API methods yielded819 results; Activity coverage was117/198 at that
checkpoint. These are bounded historical results, not a full/current
matrix pass. The preceding stage-fix runs hit50 hosted-runner
acquisition cancellations; other jobs were active, so this was not a
claimed global outage. New pushes schedule fresh CI, not an AL retry.
The general SQL-pool NRE and missing warning-reference artifacts remain
separate unresolved limitations.

Durable session presentation notes:
**api-test-enablement-presentation-notes.md**, with source-pinned
selection proof, fix/coverage inventory, helper limitations and
historical-vs-current evidence boundaries. Fresh runtime proof must
still establish the51 Expense cases and actual193-case suppression at
Expense stage.


[AB#646383](https://dynamicssmb2.visualstudio.com/1fcb79e7-ab07-432a-a3c6-6cf5a88ba4a5/_workitems/edit/646383)
(link only). Native stack #12327 remains microsoft#12325 → microsoft#11860 → microsoft#11224 →
microsoft#11225 → microsoft#11226 → microsoft#11227 → microsoft#11228 → microsoft#11229 → microsoft#11230 → microsoft#11322. Protected
merged microsoft#10085/microsoft#11862/microsoft#11891 and validation microsoft#11892 are untouched;
validation-only microsoft#11861/microsoft#11455 remain Do Not Merge. No new main
integration, native-group/base change, PR merge, queue operation,
Actions cancellation or manual retry was made. All prior heads remain
ancestors; source publication used backups and an atomic forward-only
push with explicit leases.

Exact current head: `bd3bbc04e13965f967a26eef435bdbf0cbc09ad7`; source
tree: `2b8c47b138846f63bd49d47188f54ea7e86c1f24`.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3952f078-a881-4da8-ad96-13b727e48a91

This branch had an error being deployed

1 failed (outdated) deployment
triage — da6d82d6 Deployed Sep 29, 2026 by AndersLarsenMicrosoft via Classify team ownership #6199
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AL: Apps (W1) Add-on apps for W1 Build: Automation Workflows and other setup in .github folder Ownership: Needs Review Ownership is Other, low confidence, or needs manual correction Team: Other GitHub request for other area than SCM, Finance or Integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants