{"record":{"id":"d15ef9a637c96778","repo":"grpc/grpc-go","slug":"extauthz-error-parsing-override-config-v-unknow","errorCode":null,"errorMessage":"extauthz: error parsing override config %v: unknown type %T, want *anypb.Any","messagePattern":"extauthz: error parsing override config (.+?): unknown type %T, want \\*anypb\\.Any","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/ext_authz/ext_authz.go","lineNumber":172,"sourceCode":"\t\tfailureModeAllowHeaderAdd:  msg.GetFailureModeAllowHeaderAdd(),\n\t\tstatusOnError:              statusOnError,\n\t\tallowedHeaders:             allowedHeaders,\n\t\tdisallowedHeaders:          disallowedHeaders,\n\t\tdecoderHeaderMutationRules: mutationRules,\n\t\tincludePeerCertificate:     msg.GetIncludePeerCertificate(),\n\t}, nil\n}\n\n// ParseFilterConfigOverride parses the provided override configuration.\n//\n// Note that ExtAuthzPerRoute is unmarshaled to verify its syntax during xDS\n// resource validation, no filter configuration object is returned. Per-route\n// disabling is supported via the generic FilterConfig wrapper mechanism rather\n// than the ExtAuthzPerRoute.disabled field directly.\nfunc (builder) ParseFilterConfigOverride(overrideCfg proto.Message) (httpfilter.FilterConfig, error) {\n\tm, ok := overrideCfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"extauthz: error parsing override config %v: unknown type %T, want *anypb.Any\", overrideCfg, overrideCfg)\n\t}\n\tmsg := new(v3extauthzpb.ExtAuthzPerRoute)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: failed to unmarshal override config %v: %v\", overrideCfg, err)\n\t}\n\treturn nil, nil\n}\n\nfunc (builder) IsTerminal() bool {\n\treturn false\n}\n","sourceCodeStart":154,"sourceCodeEnd":184,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/ext_authz/ext_authz.go#L154-L184","documentation":"ParseFilterConfigOverride expected the override configuration wrapped as *anypb.Any but received a different concrete proto type (ext_authz.go:170-172). Per-route filter override configs are transported as Any-wrapped messages in the xDS protocol.","triggerScenarios":"The httpfilter framework calls ParseFilterConfigOverride with a proto.Message whose concrete type is not *anypb.Any (e.g. a bare ExtAuthzPerRoute proto passed by custom integration or test code).","commonSituations":"Custom httpfilter integration that unwraps Any before dispatching to the override parser; incorrect framework wiring; test code passing a bare ExtAuthzPerRoute proto instead of wrapping it.","solutions":["Ensure the httpfilter framework passes *anypb.Any to ParseFilterConfigOverride","Wrap the override config proto with anypb.New() before calling the parser in test code","Do not manually unwrap Any before dispatching to filter override parsers"],"exampleFix":"// before — bare proto passed\noverride := &v3extauthzpb.ExtAuthzPerRoute{}\nfc, err := builder{}.ParseFilterConfigOverride(override)\n\n// after — wrap in Any first\nanyOverride, _ := anypb.New(override)\nfc, err := builder{}.ParseFilterConfigOverride(anyOverride)","handlingStrategy":"type-guard","validationCode":null,"typeGuard":"// Ensure the override config is *anypb.Any before passing to the parser.\nfunc isAnyProto(msg proto.Message) bool {\n    _, ok := msg.(*anypb.Any)\n    return ok\n}","tryCatchPattern":null,"preventionTips":["Always pass *anypb.Any to httpfilter override parsers","Use anypb.New() to wrap override protos in test code","Do not manually unwrap Any messages before dispatching to filter override parsers"],"tags":["ext-authz","xds","http-filter","type-assertion","per-route"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}