Release v22.8.1
Summary
ARCCHR0009 judged a command property by its name alone. Its first contact with real code found two kinds of false positive: properties like AccessTokenExpiresAt, which contain the word "token" and hold a DateTimeOffset, and properties whose secret is wrapped in a concept the application had already marked — which the runtime honors but the analyzer did not, so it reported correct code. Both are fixed, and the documentation now says what to do when the rule is still wrong.
Changed
ARCCHR0009no longer reports a property whose type cannot hold a secret — a date, a duration, a number, a bool, aGuidor an enum — however it is named, soAccessTokenExpiresAtis left alone whileAccessTokenis still reported (#2625)ARCCHR0009honors[NotAudited]and[PII]on the property's type, matching what the runtime already withholds, so marking a concept once covers every command that takes one (#2625)ARCCHR0009judges a concept by the value it wraps, so aConceptAs<string>holding a token is reported and aConceptAs<DateTimeOffset>is not (#2625)
Fixed
- The
ARCCHR0009documentation told you to mark a false positive[NotAudited], which silences the warning by withholding the value rather than recording it; it now says to suppress the diagnostic and keep the value (#2625)