{"record":{"id":"3d1a2113372f3b34","repo":"grpc/grpc-go","slug":"failed-to-parse-auditcondition-v-allowed-values","errorCode":null,"errorMessage":"failed to parse AuditCondition %v. Allowed values {NONE, ON_DENY, ON_ALLOW, ON_DENY_AND_ALLOW}","messagePattern":"failed to parse AuditCondition (.+?)\\. Allowed values (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"authz/rbac_translator.go","lineNumber":299,"sourceCode":"\t\tpolicies[policyName] = &v3rbacpb.Policy{\n\t\t\tPrincipals:  []*v3rbacpb.Principal{parsePeer(rule.Source)},\n\t\t\tPermissions: []*v3rbacpb.Permission{permission},\n\t\t}\n\t}\n\treturn policies, nil\n}\n\n// Parse auditLoggingOptions to the associated RBAC protos. The single\n// auditLoggingOptions results in two different parsed protos, one for the allow\n// policy and one for the deny policy\nfunc (options *auditLoggingOptions) toProtos() (allow *v3rbacpb.RBAC_AuditLoggingOptions, deny *v3rbacpb.RBAC_AuditLoggingOptions, err error) {\n\tallow = &v3rbacpb.RBAC_AuditLoggingOptions{}\n\tdeny = &v3rbacpb.RBAC_AuditLoggingOptions{}\n\n\tif options.AuditCondition != \"\" {\n\t\trbacCondition, ok := v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition_value[options.AuditCondition]\n\t\tif !ok {\n\t\t\treturn nil, nil, fmt.Errorf(\"failed to parse AuditCondition %v. Allowed values {NONE, ON_DENY, ON_ALLOW, ON_DENY_AND_ALLOW}\", options.AuditCondition)\n\t\t}\n\t\tallow.AuditCondition = v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition)\n\t\tdeny.AuditCondition = toDenyCondition(v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition))\n\t}\n\n\tfor i, config := range options.AuditLoggers {\n\t\tif config.Name == \"\" {\n\t\t\treturn nil, nil, fmt.Errorf(\"missing required field: name in audit_logging_options.audit_loggers[%v]\", i)\n\t\t}\n\t\tif config.Config == nil {\n\t\t\tconfig.Config = &structpb.Struct{}\n\t\t}\n\t\ttypedStruct := &v1xdsudpatypepb.TypedStruct{\n\t\t\tTypeUrl: typeURLPrefix + config.Name,\n\t\t\tValue:   config.Config,\n\t\t}\n\t\tcustomConfig, err := anypb.New(typedStruct)\n\t\tif err != nil {","sourceCodeStart":281,"sourceCodeEnd":317,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/authz/rbac_translator.go#L281-L317","documentation":"Returned by auditLoggingOptions.toProtos (rbac_translator.go:299) when audit_logging_options.audit_condition is non-empty but not one of the recognized enum strings. The parser looks up the value in the RBAC_AuditLoggingOptions_AuditCondition_value map; an unknown string yields this error listing the allowed set {NONE, ON_DENY, ON_ALLOW, ON_DENY_AND_ALLOW}.","triggerScenarios":"Policy JSON with audit_logging_options.audit_condition set to a misspelled or wrong-case value, e.g. \"on_deny\" (lowercase) or \"Always\".","commonSituations":"Case mismatch (enum values are uppercase); typo; copying from docs that used a different casing; stale value from an older spec.","solutions":["Set audit_condition to one of the exact uppercase values: \"NONE\", \"ON_DENY\", \"ON_ALLOW\", \"ON_DENY_AND_ALLOW\", or omit it (empty means NONE).","Lint the policy so any audit_condition is validated against the allowed enum set."],"exampleFix":"// before\n\"audit_logging_options\": { \"audit_condition\": \"on_deny\" }\n\n// after\n\"audit_logging_options\": { \"audit_condition\": \"ON_DENY\" }","handlingStrategy":"validation","validationCode":"var allowedAudit = map[string]bool{\"\": true, \"NONE\": true, \"ON_DENY\": true, \"ON_ALLOW\": true, \"ON_DENY_AND_ALLOW\": true}\nfunc validAuditCondition(v string) bool { return allowedAudit[strings.ToUpper(v)] && v == strings.ToUpper(v) }","typeGuard":null,"tryCatchPattern":"interceptor, err := authz.NewStatic(policyJSON)\nif err != nil {\n    if strings.Contains(err.Error(), \"AuditCondition\") {\n        // set audit_condition to one of NONE/ON_DENY/ON_ALLOW/ON_DENY_AND_ALLOW\n    }\n}","preventionTips":["Use exact uppercase enum values for audit_condition.","Omit audit_condition entirely to default to NONE.","Lint the policy against the allowed enum set."],"tags":["grpc","authz","rbac","audit","policy","config","go"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}