Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 26 additions & 6 deletions cedar-policy-core/src/parser/cst_to_ast.rs
Original file line number Diff line number Diff line change
Expand Up @@ -2124,12 +2124,13 @@ impl Node<Option<cst::Name>> {
// signaled when the `Node` without data was created
let name = self.as_inner()?;

let path: Vec<_> = name
.path
.iter()
.filter_map(|i| i.to_valid_ident(errs))
.collect();
if path.len() > 0 {
for id in &name.path {
// We don't need the actual ident, but we want to report an error
// if they're invalid.
id.to_valid_ident(errs);
}

if !name.path.is_empty() {
errs.push(self.to_ast_err(ToASTErrorKind::InvalidPath));
return None;
}
Expand Down Expand Up @@ -4730,4 +4731,23 @@ mod tests {
expect_arbitrary_var("foo::bar");
expect_arbitrary_var("foo::bar::baz");
}

#[test]
fn reserved_ident_var() {
#[track_caller]
fn expect_reserved_ident(name: &str, reserved: &str) {
assert_matches!(parse_expr(name), Err(e) => {
expect_err(name, &e, &ExpectedErrorMessage::error(
&format!("this identifier is reserved and cannot be used: `{reserved}`"),
));
})
}
expect_reserved_ident("if::principal", "if");
expect_reserved_ident("then::action", "then");
expect_reserved_ident("else::resource", "else");
expect_reserved_ident("true::context", "true");
expect_reserved_ident("false::bar::principal", "false");
expect_reserved_ident("foo::in::principal", "in");
expect_reserved_ident("foo::is::bar::principal", "is");
}
}
5 changes: 4 additions & 1 deletion cedar-policy/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,10 @@ method checks the request against the schema provided and the
- Action entities in the store will pass schema-based validation without requiring
the transitive closure to be pre-computed. (#581, resolving #285)
- Variables qualified by a namespace with a single element are correctly
rejected. E.g., `foo::principal` is an error and is not parsed as `principal`.
rejected. E.g., `foo::principal` is an error and is not parsed as
`principal`. Variables qualified by a namespace of any size comprised entirely
of Cedar keywords are correctly rejected. E.g., `if::then::else::principal` is an error.
(#594 and #596)

## [3.0.1] - 2023-12-21
Cedar Language Version: 3.0.0
Expand Down