{"record":{"id":"c53e6924ca61b84d","repo":"grpc/grpc-go","slug":"name-is-not-present","errorCode":null,"errorMessage":"\"name\" is not present","messagePattern":"\"name\" is not present","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"authz/rbac_translator.go","lineNumber":370,"sourceCode":"\t\treturn v3rbacpb.RBAC_AuditLoggingOptions_ON_DENY\n\tdefault:\n\t\treturn v3rbacpb.RBAC_AuditLoggingOptions_NONE\n\t}\n}\n\n// translatePolicy translates SDK authorization policy in JSON format to two\n// Envoy RBAC polices (deny followed by allow policy) or only one Envoy RBAC\n// allow policy. Also returns the overall policy name. If the input policy\n// cannot be parsed or is invalid, an error will be returned.\nfunc translatePolicy(policyStr string) ([]*v3rbacpb.RBAC, string, error) {\n\tpolicy := &authorizationPolicy{}\n\td := json.NewDecoder(bytes.NewReader([]byte(policyStr)))\n\td.DisallowUnknownFields()\n\tif err := d.Decode(policy); err != nil {\n\t\treturn nil, \"\", fmt.Errorf(\"failed to unmarshal policy: %v\", err)\n\t}\n\tif policy.Name == \"\" {\n\t\treturn nil, \"\", fmt.Errorf(`\"name\" is not present`)\n\t}\n\tif len(policy.AllowRules) == 0 {\n\t\treturn nil, \"\", fmt.Errorf(`\"allow_rules\" is not present`)\n\t}\n\tallowLogger, denyLogger, err := policy.AuditLoggingOptions.toProtos()\n\tif err != nil {\n\t\treturn nil, \"\", err\n\t}\n\trbacs := make([]*v3rbacpb.RBAC, 0, 2)\n\tif len(policy.DenyRules) > 0 {\n\t\tdenyPolicies, err := parseRules(policy.DenyRules, policy.Name)\n\t\tif err != nil {\n\t\t\treturn nil, \"\", fmt.Errorf(`\"deny_rules\" %v`, err)\n\t\t}\n\t\tdenyRBAC := &v3rbacpb.RBAC{\n\t\t\tAction:              v3rbacpb.RBAC_DENY,\n\t\t\tPolicies:            denyPolicies,\n\t\t\tAuditLoggingOptions: denyLogger,","sourceCodeStart":352,"sourceCodeEnd":388,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/authz/rbac_translator.go#L352-L388","documentation":"Returned by translatePolicy (rbac_translator.go:370) when the top-level policy decoded successfully but its \"name\" field is empty. The policy name is required and is used as the prefix for every generated RBAC policy name, so an empty name is rejected before any rules are translated.","triggerScenarios":"Valid JSON that decodes into authorizationPolicy but omits the top-level \"name\" field or sets it to \"\".","commonSituations":"Policy template missing the name; refactoring that moved name under a nested object; copy-paste from a fragment that lacked name.","solutions":["Add a non-empty top-level \"name\" to the policy JSON, e.g. \"name\": \"my-service-authz\".","Lint policies to require a non-empty top-level name."],"exampleFix":"// before\n{ \"allow_rules\": [ {\"name\":\"r\",\"request\":{\"paths\":[\"/\"]}} ] }\n\n// after\n{ \"name\": \"svc-authz\", \"allow_rules\": [ {\"name\":\"r\",\"request\":{\"paths\":[\"/\"]}} ] }","handlingStrategy":"validation","validationCode":"if p.Name == \"\" {\n    return errors.New(\"top-level policy name required\")\n}","typeGuard":null,"tryCatchPattern":"interceptor, err := authz.NewStatic(policyJSON)\nif err != nil {\n    if err.Error() == `\"name\" is not present` {\n        // add a top-level \"name\" to the policy\n    }\n}","preventionTips":["Always set a non-empty top-level name on the policy.","Lint policies for the required top-level name field."],"tags":["grpc","authz","rbac","policy","config","go"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}