Skip to content

Bug 647079: [28.x] Fix site scoped contextinfo - #10309

Merged
Jesper Schulz-Wedde (JesperSchulz) merged 1 commit into
releases/28.xfrom
bugs/647079-28xBackportOf630670
Aug 20, 2026
Merged

Bug 647079: [28.x] Fix site scoped contextinfo#10309
Jesper Schulz-Wedde (JesperSchulz) merged 1 commit into
releases/28.xfrom
bugs/647079-28xBackportOf630670

Conversation

@JesperSchulz

@JesperSchulz Jesper Schulz-Wedde (JesperSchulz) commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

Backport of #9454 to releases/28.x for the September release (28.5).

SharePoint Uri Builder.GetHost() intentionally returns only the hostname, but request-digest calls used it for /_api/contextinfo. For site-scoped URLs such as https://tenant.sharepoint.com/sites/site the request therefore targeted the tenant root instead of the configured site, so folder and list creation failed when the Entra ID application was granted only Sites.Selected permissions on Microsoft Graph and SharePoint.

This adds a site-base URL accessor and uses it for request-digest acquisition in CreateList, both CreateListItem overloads, CreateFolder and UpdateListItemMetaDataField. GetHost() is unchanged, so existing hostname-only consumers keep their behavior.

Regression tests verify that contextinfo requests retain the configured /sites/<site> path.

Work Item(s)

Fixes AB#647079 (backport of AB#630670)

Cherry-pick

Clean cherry-pick of 6561ab7 (-x), no conflicts and no manual edits. The diff is identical to the change merged to main: 4 files, 62 insertions, 5 deletions.

Risk & compatibility

Internal URI-construction change only. No schema, data-upgrade, permission or public API contract changes.

## What & why

This fixes SharePoint request-digest acquisition for site-scoped
SharePoint URLs.

`SharePoint Uri Builder`.GetHost() intentionally returns only the
hostname, but request-digest calls used it for `/_api/contextinfo`. For
URLs such as `https://tenant.sharepoint.com/sites/site`, this caused the
request to target the tenant root instead of the configured site.

The change adds a site-base URL accessor and uses it for request-digest
acquisition in CreateList, both CreateListItem overloads, CreateFolder,
and UpdateListItemMetaDataField. `GetHost()` remains unchanged for
callers that require hostname-only behavior.

Regression tests verify that contextinfo requests retain the configured
`/sites/<site>` path.

## Linked work

Fixes #8932

## How I validated this

- [x] I read the full diff and it contains only changes I intended.
- [x] I built the affected app(s) locally with zero compilation errors.
- [x] I ran the change in Business Central and confirmed it behaves as
expected.
- [x] I added or updated tests for the new behavior, or explained below
why none are needed.

**What I tested and the outcome**

- Built the affected System Application and test applications locally
with zero compilation errors.
- Published a temporary System Application build to a disposable local
BC29 container using normal synchronization and upgrade semantics.
- Ran the SharePoint Client Test codeunit (132970) manually in the BC
Test Tool.
- Confirmed the regression before the fix:
  - Expected: site-scoped `.../sites/<site>/_api/contextinfo/`
  - Actual: tenant-root `.../_api/contextinfo/`
- Published the fixed System Application and reran the same tests.
- Confirmed that `TestCreateFolder`,
`TestCreateListRequestDigestUsesSiteScopedUrl`, and
`TestCreateListItemRequestDigestUsesSiteScopedUrl` pass with the fix
applied.
- Also verified the original scoped SharePoint scenario manually in a
disposable v28.1 container.

## Risk & compatibility

This is an internal URI-construction change with no schema,
data-upgrade, permission, or public API contract changes.

`GetHost()` is unchanged. The new site-base URL accessor is used only
for request-digest acquisition, ensuring existing hostname-only
consumers retain their behavior.
Fixes #8932 is the GitHub issue link. GitHub will automatically link it,
and close the issue when the PR is merged.

Fixes
[AB#630670](https://dynamicssmb2.visualstudio.com/1fcb79e7-ab07-432a-a3c6-6cf5a88ba4a5/_workitems/edit/630670)

(cherry picked from commit 6561ab7)
@github-actions github-actions Bot added the Integration GitHub request for Integration area label Aug 18, 2026
@JesperSchulz
Jesper Schulz-Wedde (JesperSchulz) merged commit df80e17 into releases/28.x Aug 20, 2026
124 of 132 checks passed
@JesperSchulz
Jesper Schulz-Wedde (JesperSchulz) deleted the bugs/647079-28xBackportOf630670 branch August 20, 2026 07:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AL: System Application Integration GitHub request for Integration area

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants