{"record":{"id":"bbcffdcba327dcbe","repo":"grpc/grpc-go","slug":"missing-required-field-name-in-audit-logging-opti","errorCode":null,"errorMessage":"missing required field: name in audit_logging_options.audit_loggers[%v]","messagePattern":"missing required field: name in audit_logging_options\\.audit_loggers\\[(.+?)\\]","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"authz/rbac_translator.go","lineNumber":307,"sourceCode":"// Parse auditLoggingOptions to the associated RBAC protos. The single\n// auditLoggingOptions results in two different parsed protos, one for the allow\n// policy and one for the deny policy\nfunc (options *auditLoggingOptions) toProtos() (allow *v3rbacpb.RBAC_AuditLoggingOptions, deny *v3rbacpb.RBAC_AuditLoggingOptions, err error) {\n\tallow = &v3rbacpb.RBAC_AuditLoggingOptions{}\n\tdeny = &v3rbacpb.RBAC_AuditLoggingOptions{}\n\n\tif options.AuditCondition != \"\" {\n\t\trbacCondition, ok := v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition_value[options.AuditCondition]\n\t\tif !ok {\n\t\t\treturn nil, nil, fmt.Errorf(\"failed to parse AuditCondition %v. Allowed values {NONE, ON_DENY, ON_ALLOW, ON_DENY_AND_ALLOW}\", options.AuditCondition)\n\t\t}\n\t\tallow.AuditCondition = v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition)\n\t\tdeny.AuditCondition = toDenyCondition(v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition))\n\t}\n\n\tfor i, config := range options.AuditLoggers {\n\t\tif config.Name == \"\" {\n\t\t\treturn nil, nil, fmt.Errorf(\"missing required field: name in audit_logging_options.audit_loggers[%v]\", i)\n\t\t}\n\t\tif config.Config == nil {\n\t\t\tconfig.Config = &structpb.Struct{}\n\t\t}\n\t\ttypedStruct := &v1xdsudpatypepb.TypedStruct{\n\t\t\tTypeUrl: typeURLPrefix + config.Name,\n\t\t\tValue:   config.Config,\n\t\t}\n\t\tcustomConfig, err := anypb.New(typedStruct)\n\t\tif err != nil {\n\t\t\treturn nil, nil, fmt.Errorf(\"error parsing custom audit logger config: %v\", err)\n\t\t}\n\n\t\tlogger := &v3corepb.TypedExtensionConfig{Name: config.Name, TypedConfig: customConfig}\n\t\trbacConfig := v3rbacpb.RBAC_AuditLoggingOptions_AuditLoggerConfig{\n\t\t\tIsOptional:  config.IsOptional,\n\t\t\tAuditLogger: logger,\n\t\t}","sourceCodeStart":289,"sourceCodeEnd":325,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/authz/rbac_translator.go#L289-L325","documentation":"Returned by auditLoggingOptions.toProtos (rbac_translator.go:307) when iterating audit_logging_options.audit_loggers[] and an entry has an empty Name. Each audit logger is turned into a TypedExtensionConfig whose name is the logger name (and feeds the typeURL at line 313), so a missing name is rejected at the entry's index.","triggerScenarios":"Policy JSON with audit_logging_options.audit_loggers[] containing an entry without \"name\", e.g. {\"config\": {...}}.","commonSituations":"Authoring a custom audit logger block and omitting the registered logger name; refactoring that renamed 'name' to something else.","solutions":["Add the registered audit logger \"name\" to the entry at the reported index.","Confirm the name matches a logger registered via authz audit logger registration in your binary."],"exampleFix":"// before\n\"audit_loggers\": [ { \"config\": { }, \"is_optional\": true } ]\n\n// after\n\"audit_loggers\": [ { \"name\": \"logger1\", \"config\": { }, \"is_optional\": true } ]","handlingStrategy":"validation","validationCode":"for i, l := range auditLoggers {\n    if l.Name == \"\" {\n        return fmt.Errorf(\"audit_loggers[%d]: name required\", i)\n    }\n}","typeGuard":null,"tryCatchPattern":"interceptor, err := authz.NewStatic(policyJSON)\nif err != nil {\n    if strings.Contains(err.Error(), \"audit_loggers[\") {\n        // add the registered logger name to the flagged entry\n    }\n}","preventionTips":["Always set \"name\" on each audit_loggers entry to a registered logger name.","Validate policy that includes audit_logging_options before deploy."],"tags":["grpc","authz","rbac","audit","policy","config","go"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}