Anchor streaming destination schema patterns to whole strings

What does this MR do and why?

JSON schema pattern constraints in the audit event streaming config schemas were anchored with ^/$. json_schemer compiles a pattern with its default regexp_resolver of "ruby", so those bind to line boundaries — a value only had to match on one of its lines, leaving anything after a newline unvalidated. "validbucket\nevil" was accepted for bucketName.

Anchors the four affected fields with \A/\z:

Schema Field
aws accessKeyXid, bucketName
gcp googleProjectIdName, logIdName

awsRegion was already fixed in !249803 (merged).

Deliberate choices

The AWS and GCP schema validations are now skipped while config is untouched. Tightening a pattern can reject a value an existing row already stores, and the schema validation re-ran on every save — so such a destination could not be renamed or even deactivated (Activatable#deactivate! is update!(active: false)). Any change to config still revalidates the whole config, so a rejected value cannot be introduced. This mirrors the existing guard in config_is_properly_formatted and the gating applied to awsRegion.

The HTTP schema is left alone. Its url pattern has no closing anchor at all and its header value pattern is a three-branch alternation; both need semantic decisions rather than a mechanical change. Worth a follow-up — the header value is the highest injection risk of the set.

References

Screenshots or screen recordings

No UI change.

How to set up and validate locally

d = build(:audit_events_group_external_streaming_destination, :aws)
d.config = d.config.merge('bucketName' => "validbucket\nevil")
d.valid?   # => false (was true before this change)
bundle exec rspec \
  ee/spec/models/audit_events/group/external_streaming_destination_spec.rb \
  ee/spec/models/audit_events/instance/external_streaming_destination_spec.rb

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading