Skip to content

check --references passes an entity grant whose entity or module role does not exist; exec then refuses it after earlier statements were written #1333

Description

@ynnckw

Environment: mxcli v0.25.0 (Windows amd64), Mendix 11.12.4 project, scripts under mdl 1;.

Setup (any project):

mdl 1;
create module MyModule;
create module role MyModule.User;
create persistent entity MyModule.Order (
  Status: String(50)
);

Script:

mdl 1;
grant create, delete on entity MyModule.Order to MyModule.User;
grant create on entity MyModule.NoSuchEntity to MyModule.User;
grant create on entity MyModule.Order to MyModule.NoSuchRole;

Steps: mxcli -p app.mpr check script.mdl --references, then mxcli -p app.mpr exec script.mdl.

Actual behavior:

  • check --references prints Check passed! and exits 0. Neither the unknown entity MyModule.NoSuchEntity nor the unknown module role MyModule.NoSuchRole is reported.
  • exec writes the first grant (Granted access on MyModule.Order to MyModule.User), then stops with Error: entity not found: MyModule.NoSuchEntity and exits 1. The first rule stays in the model.
  • A script holding only the third line also passes check --references, and exec refuses it with Error: module role not found: MyModule.NoSuchRole.

Expected behavior: check --references resolves the entity and the module role named in an entity grant (and revoke) the way exec does, and reports both as reference errors before anything is written. Because exec is not transactional, today a typo in a role or entity name is found only after the statements before it are already in the .mpr.

Related: #836 (cross-module role on grant execute, same check/exec gap), #1067 (a) (unqualified role name), #610 (check passes, exec fails for create association).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions