grpc/grpc-go · error
"name" is not present
Error message
"name" is not present
What it means
Returned by translatePolicy (rbac_translator.go:370) when the top-level policy decoded successfully but its "name" field is empty. The policy name is required and is used as the prefix for every generated RBAC policy name, so an empty name is rejected before any rules are translated.
Solutions
- Add a non-empty top-level "name" to the policy JSON, e.g. "name": "my-service-authz".
- Lint policies to require a non-empty top-level name.
Example fix
// before
{ "allow_rules": [ {"name":"r","request":{"paths":["/"]}} ] }
// after
{ "name": "svc-authz", "allow_rules": [ {"name":"r","request":{"paths":["/"]}} ] } Defensive patterns
Strategy: validation
Validate before calling
if p.Name == "" {
return errors.New("top-level policy name required")
} Try / catch
interceptor, err := authz.NewStatic(policyJSON)
if err != nil {
if err.Error() == `"name" is not present` {
// add a top-level "name" to the policy
}
} Prevention
- Always set a non-empty top-level name on the policy.
- Lint policies for the required top-level name field.
When it happens
Trigger: Valid JSON that decodes into authorizationPolicy but omits the top-level "name" field or sets it to "".
Common situations: Policy template missing the name; refactoring that moved name under a nested object; copy-paste from a fragment that lacked name.
Related errors
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/c53e6924ca61b84d.
Report an issue: GitHub.
Appendix: source
Thrown at authz/rbac_translator.go:370
return v3rbacpb.RBAC_AuditLoggingOptions_ON_DENY
default:
return v3rbacpb.RBAC_AuditLoggingOptions_NONE
}
}
// translatePolicy translates SDK authorization policy in JSON format to two
// Envoy RBAC polices (deny followed by allow policy) or only one Envoy RBAC
// allow policy. Also returns the overall policy name. If the input policy
// cannot be parsed or is invalid, an error will be returned.
func translatePolicy(policyStr string) ([]*v3rbacpb.RBAC, string, error) {
policy := &authorizationPolicy{}
d := json.NewDecoder(bytes.NewReader([]byte(policyStr)))
d.DisallowUnknownFields()
if err := d.Decode(policy); err != nil {
return nil, "", fmt.Errorf("failed to unmarshal policy: %v", err)
}
if policy.Name == "" {
return nil, "", fmt.Errorf(`"name" is not present`)
}
if len(policy.AllowRules) == 0 {
return nil, "", fmt.Errorf(`"allow_rules" is not present`)
}
allowLogger, denyLogger, err := policy.AuditLoggingOptions.toProtos()
if err != nil {
return nil, "", err
}
rbacs := make([]*v3rbacpb.RBAC, 0, 2)
if len(policy.DenyRules) > 0 {
denyPolicies, err := parseRules(policy.DenyRules, policy.Name)
if err != nil {
return nil, "", fmt.Errorf(`"deny_rules" %v`, err)
}
denyRBAC := &v3rbacpb.RBAC{
Action: v3rbacpb.RBAC_DENY,
Policies: denyPolicies,
AuditLoggingOptions: denyLogger,View on GitHub (pinned to 0c51461d27)