diff --git a/pkg/resources/management.cattle.io/v3/setting/validator.go b/pkg/resources/management.cattle.io/v3/setting/validator.go index 6e7c37beda..6058440db7 100644 --- a/pkg/resources/management.cattle.io/v3/setting/validator.go +++ b/pkg/resources/management.cattle.io/v3/setting/validator.go @@ -377,8 +377,8 @@ func (a *admitter) validateUserRetentionCron(s *v3.Setting) error { func (a *admitter) validateAuthUserInfoMaxAgeSeconds(s *v3.Setting) error { // We cannot use the validateDuration func since it does not allow for negative durations // which are valid for the auth-user-info-max-age-seconds setting. - if _, err := time.ParseDuration(s.Value + "s"); err != nil { - return field.TypeInvalid(valuePath, s.Value, err.Error()) + if _, err := time.ParseDuration(effectiveValue(s) + "s"); err != nil { + return field.TypeInvalid(valuePath, effectiveValue(s), err.Error()) } return nil diff --git a/pkg/resources/management.cattle.io/v3/setting/validator_test.go b/pkg/resources/management.cattle.io/v3/setting/validator_test.go index 7966d1efad..6667ba65dd 100644 --- a/pkg/resources/management.cattle.io/v3/setting/validator_test.go +++ b/pkg/resources/management.cattle.io/v3/setting/validator_test.go @@ -391,9 +391,10 @@ func (s *SettingSuite) TestValidateAuthUserInfoMaxAgeSecondsOnCreate() { func (s *SettingSuite) validateAuthUserInfoMaxAgeSeconds(op v1.Operation) { tests := []struct { - desc string - value string - allowed bool + desc string + value string + defaultValue string + allowed bool }{ { desc: "valid max age", @@ -409,6 +410,15 @@ func (s *SettingSuite) validateAuthUserInfoMaxAgeSeconds(op v1.Operation) { desc: "invalid max age", value: "foo", }, + { + desc: "empty value with default", + defaultValue: "3600", + allowed: true, + }, + { + desc: "empty value and default", + allowed: false, + }, } for _, test := range tests { @@ -425,7 +435,8 @@ func (s *SettingSuite) validateAuthUserInfoMaxAgeSeconds(op v1.Operation) { ObjectMeta: metav1.ObjectMeta{ Name: setting.AuthUserInfoMaxAgeSeconds, }, - Value: test.value, + Value: test.value, + Default: test.defaultValue, }, op, "foo", test.allowed) }) }