Skip to content

Published REST service: no way to set authentication; a non-string property value (e.g. Authentication: microflow M.F) panics the parser (visitor_rest.go) #1331

Description

@MohamedElNady

mxcli: v0.24.0 (2026-09-24T05:44:35Z) and v0.25.0 (2026-10-05T09:18:28Z)
Mendix: Studio Pro 11.14.0, MPR v2 · OS: Windows Server 2025 (10.0.26100)

Summary

Two related problems with CREATE [OR MODIFY] PUBLISHED REST SERVICE:

  1. No way to set authentication. mxcli syntax rest published lists only Path, Version, ServiceName (and Folder). Studio Pro's service has Requires authentication and the authentication methods Username and password, Active session and Custom (with an authentication Microflow) — see https://docs.mendix.com/refguide/published-rest-service/ (section "Authentication"). A service written by mxcli therefore cannot require authentication, so its operations cannot run as the caller and entity access cannot apply per caller.
  2. Any property value that is not a string literal panics the parser instead of giving a syntax error — e.g. Authentication: microflow M.F, Authentication: Basic, even Folder: microflow M.F. check and exec both crash with a nil pointer dereference in ExitCreatePublishedRestServiceStatement.

The OData service syntax already supports the equivalent (CREATE ODATA SERVICE … authentication microflow M.F), so the model side exists in mxcli.

Minimal repro (blank Mendix 11.14 project)

CREATE OR MODIFY MICROFLOW MyFirstModule.AuthMf ()
RETURNS System.User
BEGIN
  return empty;
END;
CREATE OR MODIFY MICROFLOW MyFirstModule.GetItems ()
RETURNS String
BEGIN
  return 'ok';
END;

Then:

CREATE OR MODIFY PUBLISHED REST SERVICE MyFirstModule.TestApi (
  Path: 'rest/test/v1',
  Version: '1.0.0',
  ServiceName: 'Test API',
  Authentication: microflow MyFirstModule.AuthMf
)
{
  RESOURCE 'items' {
    GET '' MICROFLOW MyFirstModule.GetItems;
  }
};

Actual

v0.24.0 (mxcli check and mxcli exec):

panic: runtime error: invalid memory address or nil pointer dereference
[signal 0xc0000005 code=0x0 addr=0x58 pc=0x7ff628e753a7]

goroutine 1 [running]:
github.com/mendixlabs/mxcli/mdl/visitor.(*Builder).ExitCreatePublishedRestServiceStatement(...)
	github.com/mendixlabs/mxcli/mdl/visitor/visitor_rest.go:360 +0x447
github.com/mendixlabs/mxcli/mdl/grammar/parser.(*CreatePublishedRestServiceStatementContext).ExitRule(...)
	github.com/mendixlabs/mxcli/mdl/grammar/parser/mdl_parser.go:116433 +0x4f
...
main.init.func65(...)
	github.com/mendixlabs/mxcli/cmd/mxcli/cmd_check.go:152 +0x94d

v0.25.0:

panic: runtime error: invalid memory address or nil pointer dereference
[signal 0xc0000005 code=0x0 addr=0x18 pc=0x7ff7e03c085c]

goroutine 1 [running]:
github.com/mendixlabs/mxcli/mdl/visitor.unquoteStringLit({0x0, 0x0})
	github.com/mendixlabs/mxcli/mdl/visitor/visitor_string_escapes.go:48 +0x1c
github.com/mendixlabs/mxcli/mdl/visitor.(*Builder).ExitCreatePublishedRestServiceStatement(...)
	github.com/mendixlabs/mxcli/mdl/visitor/visitor_rest.go:386 +0x530
...

What narrows it down

Variant v0.24.0 v0.25.0
Authentication: microflow MyFirstModule.AuthMf panic visitor_rest.go:360 panic unquoteStringLit via visitor_rest.go:386
Authentication: Basic (bare word) panic panic
Folder: microflow MyFirstModule.AuthMf (a known key, non-string value) panic panic
Authentication: 'Basic' (string literal) accepted, silently ignored (describe shows no authentication) accepted with warning MDL-V1-PROP "unknown property 'Authentication' … ignored under mdl 0", not written
clause form … ) authentication microflow MyFirstModule.AuthMf { … } (as for OData) syntax error mismatched input 'authentication' expecting '{' same
no authentication property service created; mx check 0 errors; no authentication setting same

So the panic is not specific to Authentication: the property-value path calls unquoteStringLit on a value that is not a string literal (nil token).

Expected

  • A syntax error (or MDL-V1-PROP) for a non-string value instead of a panic.
  • Authentication support on published REST services, matching Studio Pro, e.g.
    CREATE PUBLISHED REST SERVICE M.S (Path: …, Version: …, ServiceName: …) authentication basic, session | microflow M.Auth { … }
    (same shape as CREATE ODATA SERVICE), plus describe round-trip and ALTER PUBLISHED REST SERVICE … SET Authentication ….

Workaround we use

The external API is published as an OData v4 service (CREATE ODATA SERVICE … authentication microflow M.F works) with read-only entity sets and one action that dispatches to the operation microflows. A published REST facade waits for this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions