{"id":2107,"date":"2021-05-18T05:48:38","date_gmt":"2021-05-18T05:48:38","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/release-notes\/application-code-review-acr\/2-5\/"},"modified":"2023-10-11T07:55:08","modified_gmt":"2023-10-11T07:55:08","slug":"2-5","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=release-notes\/application-code-review-acr\/2-5","title":{"rendered":"2.5"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"2.5-Mendix-9-compatibility,-rules,-and-UX\">Mendix 9 compatibility, rules, and UX<\/h2>\n\n\n\n<p>Released 18th of May 2021.<\/p>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Mendix-9-compatible\">Mendix 9 compatible<\/h3>\n\n\n\n<p>We are Mendix 9 compatible\ud83c\udf89. For the early adopters out there, #gomakeit, we got your back.<\/p>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u201cThey-are-more-like-guidelines-than-actual-rules.\u201d\">\u201cThey are more like guidelines than actual rules.\u201d<\/h3>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"New\">New<\/h4>\n\n\n\n<ul class=\"wp-block-list\"><li>We added the rule: <em>Access rules with an Xpath constrain should only use read or none access.<\/em> An access rule that uses an XPath constraint should only refer to attributes and associations with <em>Read<\/em> or <em>None<\/em> access. If the XPath uses attributes or associations with\u00a0<em>Read, Write\u00a0<\/em>access, it may cause a security breach.\u00a0<\/li><li>We added the rule: <em>Minimize the use of self-relations<\/em>. Self-relations are harder to understand in the domain model and especially in XPath queries. Mendix even introduced a reversed() function to determine the direction of the XPath association to be used in a self-relation. The advice is to minimize the use. And if self relations are needed, document them well, test them well and use the allow list for the violation.<\/li><li>We added the rule: <em>Retrieve by association from persistent to non-persistent is not advised<\/em>. Non-persistent objects can be created in microflows and exist during execution in a Mendix runtime. The browser maintains a cache of non-persistent objects. However, this browser cache is cleared when the object is no longer needed. This can be on closing a page or after some time or switching a row in a grid. When the microflow retrieves the persistent entity from the database, the association from the non-persistent entity is not linked to this copy.<\/li><\/ul>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"Improved\">Improved<\/h4>\n\n\n\n<ul class=\"wp-block-list\"><li>We improved the rule: <em>Entity access default rights for new members should be None or Read<\/em>. The rule no longer generates duplicate violations\u2014this rule checks per user role since you might want to exclude specific user roles. Consequently, the rule also checks per module role since user roles can have multiple module roles. The checks are now done, and if numerous user roles or module roles match the reason text is extended:<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"806\" height=\"85\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/0.png\" alt=\"\" class=\"wp-image-2112\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/0.png 806w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/0-480x51.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 806px, 100vw\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>We improved the unique key for access rule violations. It is now per access rule instead of per entity to place specific access rule violations on the allowlist.<\/li><\/ul>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"Fixes\">Fixes<\/h4>\n\n\n\n<ul class=\"wp-block-list\"><li>We improved the rule: <em>Retrieve &amp; aggregate combo should not be nullified by using the list. <\/em>The rule no longer generates duplicate violations. If list variables are used multiple times, a number is added.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"825\" height=\"161\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/1.png\" alt=\"\" class=\"wp-image-2110\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/1.png 825w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/1-480x94.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 825px, 100vw\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>We improved the rule: <em>Microflow called from the client should apply entity access rules. <\/em>The rule no longer generates duplicate violations. All user and module roles are combined now.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"819\" height=\"118\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/2.png\" alt=\"\" class=\"wp-image-2111\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/2.png 819w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/2-480x69.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 819px, 100vw\" \/><\/figure>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"UX-improvements\">UX improvements<\/h3>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"The-myth-of-the-documentation-button\">The myth of the documentation button<\/h4>\n\n\n\n<ul class=\"wp-block-list\"><li>We know\u2026 we hid the documentation button pretty well. So well that people might even question the button&#8217;s existence as only a few have encountered it\ud83d\ude09. So about time, we shed some light on this myth. We made it easier for you to go to the documentation. When you hover over a rule, a documentation icon appears that brings you to the rule documentation. <\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"211\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/3-1024x211.png\" alt=\"\" class=\"wp-image-2113\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/3-1024x211.png 1024w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/3-980x202.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/05\/3-480x99.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"Other-improvements\">Other improvements<\/h4>\n\n\n\n<ul class=\"wp-block-list\"><li>We made sure fixed violations align with the rest of the violations.<\/li><li>You can now mark a violation as read or copy its name from the more options.<\/li><\/ul>\n\n\n\n<p>We hope you enjoy this new release as much as we enjoyed building it. Please let us know if you have any feedback. We greatly appreciate it.&nbsp;<\/p>\n","protected":false},"featured_media":0,"parent":522,"menu_order":12,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-2107","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2107"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2107"}],"version-history":[{"count":4,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2107\/revisions"}],"predecessor-version":[{"id":2122,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2107\/revisions\/2122"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/522"}],"next":[{"title":"2.4","link":"https:\/\/sdf-docs.clevr.com\/?docs=release-notes\/application-code-review-acr\/2-4","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2034"}],"prev":[{"title":"2.6","link":"https:\/\/sdf-docs.clevr.com\/?docs=release-notes\/application-code-review-acr\/2-6","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2180"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2107"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=2107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}