Menu ▾ ▴

#31 [Design] cross-company=true hardcoded on all D365 OData requests

closed
nobody
None
2026-06-13
2026-06-12
Anonymous
No

Originally created by: pyy3

Type: design / configurability

Summary

The D365 connector hardcodes cross-company=true on every OData request, fetching data across all legal entities in the environment.

Location

source-d365-fno/source_d365_fno/streams.py (~line 66) — the cross-company=true query option is a constant on the request, not a config value.

Why it matters

This is correct for the consolidation use case, but baking it in as a constant:

  • Prevents scoping a sync to a subset of legal entities (useful for large tenants or permission-limited service principals).
  • Couples a security-relevant data-scope decision to code rather than configuration.

Suggested directions

  • Expose cross-company (and optionally an explicit legal-entity allowlist) as a spec.yaml config option, defaulting to true to preserve current behavior.
  • Document the data-scope implications in the connector README.

Related

Tickets: #34

Discussion

  • Anonymous

    Anonymous - 2026-06-13

    Ticket changed by: pyy3

    • status: open --> closed
     
  • Anonymous

    Anonymous - 2026-06-13

    Originally posted by: pyy3

    Fixed in [#34] (merged to main).

     

    Related

    Tickets: #34


Log in to post a comment.