{"record":{"id":"ed5a9e62663a7ed3","repo":"grpc/grpc-go","slug":"extauthz-missing-default-value-in-filter-enabled","errorCode":null,"errorMessage":"extauthz: missing default_value in filter_enabled","messagePattern":"extauthz: missing default_value in filter_enabled","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/ext_authz/ext_authz.go","lineNumber":68,"sourceCode":"\t}\n)\n\ntype builder struct{}\n\nfunc (builder) TypeURLs() []string {\n\treturn []string{\n\t\t\"type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthz\",\n\t\t\"type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute\",\n\t}\n}\n\nfunc parseFilterEnabled(fp *v3corepb.RuntimeFractionalPercent) (fraction, error) {\n\tif fp == nil {\n\t\treturn fraction{numerator: 100, denominator: 100}, nil\n\t}\n\tfracPercent := fp.GetDefaultValue()\n\tif fracPercent == nil {\n\t\treturn fraction{}, fmt.Errorf(\"extauthz: missing default_value in filter_enabled\")\n\t}\n\n\tden := uint32(100)\n\tswitch fracPercent.GetDenominator() {\n\tcase v3typepb.FractionalPercent_TEN_THOUSAND:\n\t\tden = 10000\n\tcase v3typepb.FractionalPercent_MILLION:\n\t\tden = 1000000\n\t}\n\n\t// If the numerator exceeds the denominator, cap the fractional value at 100%.\n\tnum := min(fracPercent.GetNumerator(), den)\n\treturn fraction{numerator: num, denominator: den}, nil\n}\n\n// grpcStatusCode converts an HTTP status code to a gRPC status code.\nfunc grpcStatusCode(httpStatus int32) codes.Code {\n\tif code, ok := transport.HTTPStatusConvTab[int(httpStatus)]; ok {","sourceCodeStart":50,"sourceCodeEnd":86,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/ext_authz/ext_authz.go#L50-L86","documentation":"The ExtAuthz config includes a filter_enabled RuntimeFractionalPercent but its default_value field is nil (ext_authz.go:66-68). The default_value (a FractionalPercent) is required to compute the sampling fraction that determines what percentage of requests the authorization filter applies to.","triggerScenarios":"parseFilterEnabled is called with a non-nil RuntimeFractionalPercent whose GetDefaultValue() returns nil. This happens when the xDS server sets the filter_enabled wrapper but omits the nested default_value.","commonSituations":"xDS server configures filter_enabled but omits the nested default_value sub-message; partial or template-generated ExtAuthz config that leaves default_value unset; Envoy configuration translation bug that drops the default_value field.","solutions":["Ensure the xDS server sets filter_enabled.default_value with a numerator and denominator (e.g. {numerator: 100, denominator: HUNDRED})","If filter_enabled is not needed, leave it unset entirely — parseFilterEnabled returns 100% when the field is nil (ext_authz.go:63-65)","Check the Envoy/xDS server filter configuration template for missing default_value"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate filter_enabled has a default_value before processing.\nif fe := msg.GetFilterEnabled(); fe != nil && fe.GetDefaultValue() == nil {\n    return fmt.Errorf(\"extauthz: filter_enabled is set but missing required default_value\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Validate ExtAuthz filter config completeness on the xDS server before deployment","Use xDS config validation tools that check for required nested fields","When setting filter_enabled, always include default_value with numerator and denominator","If sampling is not needed, omit filter_enabled entirely rather than sending a partial config"],"tags":["ext-authz","xds","http-filter","configuration"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}