grpc/grpc-go · error

"name" is not present

Error message

"name" is not present

What it means

Returned by translatePolicy (rbac_translator.go:370) when the top-level policy decoded successfully but its "name" field is empty. The policy name is required and is used as the prefix for every generated RBAC policy name, so an empty name is rejected before any rules are translated.

Solutions

  1. Add a non-empty top-level "name" to the policy JSON, e.g. "name": "my-service-authz".
  2. Lint policies to require a non-empty top-level name.

Example fix

// before
{ "allow_rules": [ {"name":"r","request":{"paths":["/"]}} ] }

// after
{ "name": "svc-authz", "allow_rules": [ {"name":"r","request":{"paths":["/"]}} ] }
Defensive patterns

Strategy: validation

Validate before calling

if p.Name == "" {
    return errors.New("top-level policy name required")
}

Try / catch

interceptor, err := authz.NewStatic(policyJSON)
if err != nil {
    if err.Error() == `"name" is not present` {
        // add a top-level "name" to the policy
    }
}

Prevention

When it happens

Trigger: Valid JSON that decodes into authorizationPolicy but omits the top-level "name" field or sets it to "".

Common situations: Policy template missing the name; refactoring that moved name under a nested object; copy-paste from a fragment that lacked name.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/c53e6924ca61b84d. Report an issue: GitHub.

Appendix: source

Thrown at authz/rbac_translator.go:370

		return v3rbacpb.RBAC_AuditLoggingOptions_ON_DENY
	default:
		return v3rbacpb.RBAC_AuditLoggingOptions_NONE
	}
}

// translatePolicy translates SDK authorization policy in JSON format to two
// Envoy RBAC polices (deny followed by allow policy) or only one Envoy RBAC
// allow policy. Also returns the overall policy name. If the input policy
// cannot be parsed or is invalid, an error will be returned.
func translatePolicy(policyStr string) ([]*v3rbacpb.RBAC, string, error) {
	policy := &authorizationPolicy{}
	d := json.NewDecoder(bytes.NewReader([]byte(policyStr)))
	d.DisallowUnknownFields()
	if err := d.Decode(policy); err != nil {
		return nil, "", fmt.Errorf("failed to unmarshal policy: %v", err)
	}
	if policy.Name == "" {
		return nil, "", fmt.Errorf(`"name" is not present`)
	}
	if len(policy.AllowRules) == 0 {
		return nil, "", fmt.Errorf(`"allow_rules" is not present`)
	}
	allowLogger, denyLogger, err := policy.AuditLoggingOptions.toProtos()
	if err != nil {
		return nil, "", err
	}
	rbacs := make([]*v3rbacpb.RBAC, 0, 2)
	if len(policy.DenyRules) > 0 {
		denyPolicies, err := parseRules(policy.DenyRules, policy.Name)
		if err != nil {
			return nil, "", fmt.Errorf(`"deny_rules" %v`, err)
		}
		denyRBAC := &v3rbacpb.RBAC{
			Action:              v3rbacpb.RBAC_DENY,
			Policies:            denyPolicies,
			AuditLoggingOptions: denyLogger,

View on GitHub (pinned to 0c51461d27)