mxcli: v0.24.0 (2026-09-24T05:44:35Z) and v0.25.0 (2026-10-05T09:18:28Z)
Mendix: Studio Pro 11.14.0, MPR v2 · OS: Windows Server 2025 (10.0.26100)
Summary
Two related problems with CREATE [OR MODIFY] PUBLISHED REST SERVICE:
- No way to set authentication.
mxcli syntax rest published lists only Path, Version, ServiceName (and Folder). Studio Pro's service has Requires authentication and the authentication methods Username and password, Active session and Custom (with an authentication Microflow) — see https://docs.mendix.com/refguide/published-rest-service/ (section "Authentication"). A service written by mxcli therefore cannot require authentication, so its operations cannot run as the caller and entity access cannot apply per caller.
- Any property value that is not a string literal panics the parser instead of giving a syntax error — e.g.
Authentication: microflow M.F, Authentication: Basic, even Folder: microflow M.F. check and exec both crash with a nil pointer dereference in ExitCreatePublishedRestServiceStatement.
The OData service syntax already supports the equivalent (CREATE ODATA SERVICE … authentication microflow M.F), so the model side exists in mxcli.
Minimal repro (blank Mendix 11.14 project)
CREATE OR MODIFY MICROFLOW MyFirstModule.AuthMf ()
RETURNS System.User
BEGIN
return empty;
END;
CREATE OR MODIFY MICROFLOW MyFirstModule.GetItems ()
RETURNS String
BEGIN
return 'ok';
END;
Then:
CREATE OR MODIFY PUBLISHED REST SERVICE MyFirstModule.TestApi (
Path: 'rest/test/v1',
Version: '1.0.0',
ServiceName: 'Test API',
Authentication: microflow MyFirstModule.AuthMf
)
{
RESOURCE 'items' {
GET '' MICROFLOW MyFirstModule.GetItems;
}
};
Actual
v0.24.0 (mxcli check and mxcli exec):
panic: runtime error: invalid memory address or nil pointer dereference
[signal 0xc0000005 code=0x0 addr=0x58 pc=0x7ff628e753a7]
goroutine 1 [running]:
github.com/mendixlabs/mxcli/mdl/visitor.(*Builder).ExitCreatePublishedRestServiceStatement(...)
github.com/mendixlabs/mxcli/mdl/visitor/visitor_rest.go:360 +0x447
github.com/mendixlabs/mxcli/mdl/grammar/parser.(*CreatePublishedRestServiceStatementContext).ExitRule(...)
github.com/mendixlabs/mxcli/mdl/grammar/parser/mdl_parser.go:116433 +0x4f
...
main.init.func65(...)
github.com/mendixlabs/mxcli/cmd/mxcli/cmd_check.go:152 +0x94d
v0.25.0:
panic: runtime error: invalid memory address or nil pointer dereference
[signal 0xc0000005 code=0x0 addr=0x18 pc=0x7ff7e03c085c]
goroutine 1 [running]:
github.com/mendixlabs/mxcli/mdl/visitor.unquoteStringLit({0x0, 0x0})
github.com/mendixlabs/mxcli/mdl/visitor/visitor_string_escapes.go:48 +0x1c
github.com/mendixlabs/mxcli/mdl/visitor.(*Builder).ExitCreatePublishedRestServiceStatement(...)
github.com/mendixlabs/mxcli/mdl/visitor/visitor_rest.go:386 +0x530
...
What narrows it down
| Variant |
v0.24.0 |
v0.25.0 |
Authentication: microflow MyFirstModule.AuthMf |
panic visitor_rest.go:360 |
panic unquoteStringLit via visitor_rest.go:386 |
Authentication: Basic (bare word) |
panic |
panic |
Folder: microflow MyFirstModule.AuthMf (a known key, non-string value) |
panic |
panic |
Authentication: 'Basic' (string literal) |
accepted, silently ignored (describe shows no authentication) |
accepted with warning MDL-V1-PROP "unknown property 'Authentication' … ignored under mdl 0", not written |
clause form … ) authentication microflow MyFirstModule.AuthMf { … } (as for OData) |
syntax error mismatched input 'authentication' expecting '{' |
same |
| no authentication property |
service created; mx check 0 errors; no authentication setting |
same |
So the panic is not specific to Authentication: the property-value path calls unquoteStringLit on a value that is not a string literal (nil token).
Expected
- A syntax error (or MDL-V1-PROP) for a non-string value instead of a panic.
- Authentication support on published REST services, matching Studio Pro, e.g.
CREATE PUBLISHED REST SERVICE M.S (Path: …, Version: …, ServiceName: …) authentication basic, session | microflow M.Auth { … }
(same shape as CREATE ODATA SERVICE), plus describe round-trip and ALTER PUBLISHED REST SERVICE … SET Authentication ….
Workaround we use
The external API is published as an OData v4 service (CREATE ODATA SERVICE … authentication microflow M.F works) with read-only entity sets and one action that dispatches to the operation microflows. A published REST facade waits for this issue.
mxcli: v0.24.0 (2026-09-24T05:44:35Z) and v0.25.0 (2026-10-05T09:18:28Z)
Mendix: Studio Pro 11.14.0, MPR v2 · OS: Windows Server 2025 (10.0.26100)
Summary
Two related problems with
CREATE [OR MODIFY] PUBLISHED REST SERVICE:mxcli syntax rest publishedlists onlyPath,Version,ServiceName(andFolder). Studio Pro's service has Requires authentication and the authentication methods Username and password, Active session and Custom (with an authentication Microflow) — see https://docs.mendix.com/refguide/published-rest-service/ (section "Authentication"). A service written by mxcli therefore cannot require authentication, so its operations cannot run as the caller and entity access cannot apply per caller.Authentication: microflow M.F,Authentication: Basic, evenFolder: microflow M.F.checkandexecboth crash with a nil pointer dereference inExitCreatePublishedRestServiceStatement.The OData service syntax already supports the equivalent (
CREATE ODATA SERVICE … authentication microflow M.F), so the model side exists in mxcli.Minimal repro (blank Mendix 11.14 project)
Then:
Actual
v0.24.0 (
mxcli checkandmxcli exec):v0.25.0:
What narrows it down
Authentication: microflow MyFirstModule.AuthMfvisitor_rest.go:360unquoteStringLitviavisitor_rest.go:386Authentication: Basic(bare word)Folder: microflow MyFirstModule.AuthMf(a known key, non-string value)Authentication: 'Basic'(string literal)describeshows no authentication)… ) authentication microflow MyFirstModule.AuthMf { … }(as for OData)mismatched input 'authentication' expecting '{'mx check0 errors; no authentication settingSo the panic is not specific to
Authentication: the property-value path callsunquoteStringLiton a value that is not a string literal (nil token).Expected
CREATE PUBLISHED REST SERVICE M.S (Path: …, Version: …, ServiceName: …) authentication basic, session | microflow M.Auth { … }(same shape as
CREATE ODATA SERVICE), plusdescriberound-trip andALTER PUBLISHED REST SERVICE … SET Authentication ….Workaround we use
The external API is published as an OData v4 service (
CREATE ODATA SERVICE … authentication microflow M.Fworks) with read-only entity sets and one action that dispatches to the operation microflows. A published REST facade waits for this issue.