• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

nats-io / nats-server / 35819710081
81%

Build:
DEFAULT BRANCH: main
Ran 23 Sep 2026 05:52AM UTC
Jobs 1
Files 66
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

22 Sep 2026 12:22PM UTC coverage: 82.783% (-0.06%) from 82.842%
35819710081

push

github

web-flow
[FIXED] LeafNode: Publish permissions checked against pre-transform subject (#8530)

Resolves #4608

## Problem

When a message is delivered to a leafnode, it may have undergone a
subject transformation. Today, the code performs the publish permissions
check against the original pre-transform subject, which is never sent to
the leafnode.

This bug requires users to include both the pre- and post-transform
subjects in the allow list for leafnodes to receive messages, which is a
security concern because it widens the scope of allowed subjects beyond
what is actually intended to travel through the leafnode connection.

## Fix

The fix is to extract the logic from `msgHeaderForRouteOrLeaf()`, which
already correctly handles the post-transform subject, and use it in
`deliverMsg()` for the publish permissions check when delivering
messages to a leafnode. By extracting the pre-existing logic into its
own function without changing semantics, we ensure it stays consistent
between both call sites and always uses the post-transform subject for
the check.

## Backwards Compatibility

This fix only removes the need to include the pre-transform subject in
the allow list. It does not break existing setups, since such setups
previously had to allow both the pre- and post-transform subjects for
leafnodes to receive messages at all. Allowing only the post-transform
subject results in the leaf server rejecting the message silently, apart
from a debug log. Allowing only the pre-transform subject lets the
message leave the leaf server, but the hub then rejects it with a
`Publish Violation` before closing the connection.

The same holds for gateway routed subjects. The check now uses exactly
the subject that goes on the wire, which is the subject the hub
evaluates as well. Any setup in which a message actually reached the hub
must therefore already allow that subject.

## Regression Test

`TestLeafNodePermsWithImportSubjectTransform` verifies that a message
with a transfor... (continued)

71930 of 86890 relevant lines covered (82.78%)

334191.27 hits per line

Coverage Regressions

Lines Coverage ∆ File
725
86.4
0.21% src/github.com/nats-io/nats-server/server/stream.go
554
55.38
-0.12% src/github.com/nats-io/nats-server/server/jetstream_errors_generated.go
143
92.93
-0.09% src/github.com/nats-io/nats-server/server/client.go
77
82.76
-1.66% src/github.com/nats-io/nats-server/server/raft.go
40
82.92
-0.11% src/github.com/nats-io/nats-server/server/jetstream_cluster.go
6
78.69
-0.04% src/github.com/nats-io/nats-server/server/filestore.go
5
85.91
-0.1% src/github.com/nats-io/nats-server/server/accounts.go
5
87.43
0.11% src/github.com/nats-io/nats-server/server/consumer.go
5
86.58
0.0% src/github.com/nats-io/nats-server/server/monitor.go
4
84.59
-0.2% src/github.com/nats-io/nats-server/server/jetstream.go
2
94.06
-0.1% src/github.com/nats-io/nats-server/server/gateway.go
1
85.33
-0.05% src/github.com/nats-io/nats-server/server/events.go
1
88.88
-0.03% src/github.com/nats-io/nats-server/server/mqtt.go
Jobs
ID Job ID Ran Files Coverage
1 35819710081.1 23 Sep 2026 05:52AM UTC 66
82.78
GitHub Action Run
Source Files on build 35819710081
  • Tree
  • List 66
  • Changed 16
  • Source Changed 3
  • Coverage Changed 16
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35819710081
  • edb1b17a on github
  • Prev Build on main (#35688130530)
  • Next Build on main (#35957096014)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc