{"record":{"id":"9c7180e52cf3a160","repo":"grpc/grpc-go","slug":"d-name-is-not-present","errorCode":null,"errorMessage":"%d: \"name\" is not present","messagePattern":"(.+?): \"name\" is not present","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"authz/rbac_translator.go","lineNumber":274,"sourceCode":"\t\t\treturn nil, err\n\t\t}\n\t\tand = append(and, permissionAnd(headers))\n\t}\n\tif len(and) > 0 {\n\t\treturn permissionAnd(and), nil\n\t}\n\treturn &v3rbacpb.Permission{\n\t\tRule: &v3rbacpb.Permission_Any{\n\t\t\tAny: true,\n\t\t},\n\t}, nil\n}\n\nfunc parseRules(rules []rule, prefixName string) (map[string]*v3rbacpb.Policy, error) {\n\tpolicies := make(map[string]*v3rbacpb.Policy)\n\tfor i, rule := range rules {\n\t\tif rule.Name == \"\" {\n\t\t\treturn policies, fmt.Errorf(`%d: \"name\" is not present`, i)\n\t\t}\n\t\tpermission, err := parseRequest(rule.Request)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"%d: %v\", i, err)\n\t\t}\n\t\tpolicyName := prefixName + \"_\" + rule.Name\n\t\tpolicies[policyName] = &v3rbacpb.Policy{\n\t\t\tPrincipals:  []*v3rbacpb.Principal{parsePeer(rule.Source)},\n\t\t\tPermissions: []*v3rbacpb.Permission{permission},\n\t\t}\n\t}\n\treturn policies, nil\n}\n\n// Parse auditLoggingOptions to the associated RBAC protos. The single\n// auditLoggingOptions results in two different parsed protos, one for the allow\n// policy and one for the deny policy\nfunc (options *auditLoggingOptions) toProtos() (allow *v3rbacpb.RBAC_AuditLoggingOptions, deny *v3rbacpb.RBAC_AuditLoggingOptions, err error) {","sourceCodeStart":256,"sourceCodeEnd":292,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/authz/rbac_translator.go#L256-L292","documentation":"Returned by parseRules (rbac_translator.go:274) when iterating allow_rules / deny_rules and a rule has an empty Name field. Each rule must have a name because it becomes the RBAC policy key (prefixed with the policy name at line 280); an empty name would collide and is rejected at the zero-based index i.","triggerScenarios":"An allow_rules[] or deny_rules[] entry missing \"name\" or with \"name\":\"\" in the policy JSON.","commonSituations":"Hand-authored policy; templated rules that omit name; refactoring that renamed fields.","solutions":["Add a unique, non-empty \"name\" to the rule at the reported index.","Lint the policy so every rule in allow_rules/deny_rules has a non-empty name and names are unique within their list."],"exampleFix":"// before\n\"allow_rules\": [ { \"request\": { \"paths\": [\"/foo\"] } } ]\n\n// after\n\"allow_rules\": [ { \"name\": \"allow_foo\", \"request\": { \"paths\": [\"/foo\"] } } ]","handlingStrategy":"validation","validationCode":"func validRule(r struct{ Name string }) error {\n    if strings.TrimSpace(r.Name) == \"\" {\n        return errors.New(\"rule name required\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"interceptor, err := authz.NewStatic(policyJSON)\nif err != nil {\n    if strings.Contains(err.Error(), `\"name\" is not present`) {\n        // the offending rule lacks a name; add one\n    }\n}","preventionTips":["Require a unique, non-empty name on every allow/deny rule.","Lint policies for empty or duplicate rule names before deploy."],"tags":["grpc","authz","rbac","policy","config","go"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}