# check\*Password query is rewritten into invalid DQL query

**URL:** <https://discuss.dgraph.io/t/check-password-query-is-rewritten-into-invalid-dql-query/15234>\
**Category:** Dgraph\
**Tags:** graphql, dgraph, kind:bug\
**Created:** [August 8, 2021, 12:01pm UTC](https://discuss.dgraph.io/t/check-password-query-is-rewritten-into-invalid-dql-query/15234 "2021-08-08T12:01:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hastri](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/hastri/32/8697_2.png) [@hastri](https://discuss.dgraph.io/u/hastri)\
**Post date:** [August 8, 2021, 12:01pm UTC](https://discuss.dgraph.io/t/check-password-query-is-rewritten-into-invalid-dql-query/15234/1 "2021-08-08T12:01:23Z")

</div>

## Report a Dgraph Bug

### What version of Dgraph are you using?

Docker Image dgraph/standalone

#21.03.1

```auto
{
  "errors": [
    {
      "message": "Dgraph query failed because Dgraph execution failed because Variables are not used properly. \nDefined:[Role_Auth1 pwd]\nUsed:[UserRoot pwd]\n",
      "path": [
        "checkUserPassword"
      ]
    }
  ],
  "extensions": {
    "tracing": {
      "version": 1,
      "startTime": "2021-08-08T11:43:59.3472973Z",
      "endTime": "2021-08-08T11:43:59.347781Z",
      "duration": 483700,
      "execution": {
        "resolvers": [
          {
            "path": [
              "checkUserPassword"
            ],
            "parentType": "Query",
            "fieldName": "checkUserPassword",
            "returnType": "User",
            "startOffset": 99500,
            "duration": 375200,
            "dgraph": [
              {
                "label": "query",
                "startOffset": 255300,
                "duration": 166200
              }
            ]
          }
        ]
      }
    }
  }
}

```

### Have you tried reproducing the issue with the latest release?

### What is the hardware spec (RAM, OS)?

### Steps to reproduce the issue (command/config used to run Dgraph).

GraphQL-Schema

```auto
type User @secret(field: "password")
 {
  name: String! @id
	roles: [Role!]! 
}

type Role 
@auth(
  query: { 
		rule: """
query($user: String!) {
	queryRole(filter: { name: { eq: $user }}) {
			name
	}
}"""	
		}	
) {
	name: String! @id
}

# Dgraph.Authorization {"VerificationKey":"secret","Header":"header","Namespace":"domain","Algo":"HS256"}

```

query (with valid jwt) e.g. eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJleHAiOjE2NTExMTExMTEsInN1YiI6IiIsImRvbWFpbiI6eyJ1c2VyIjoiIn19.DsfOGu34W\_Ju3cCDRwGQvmVghsb2zyCsd-AFq2dNMVE

```auto
query checkUser {
  checkUserPassword(name: "", password: "") {
    name
    roles {name}
  }
}

```

### Expected behaviour and actual result.

```auto
{
  "data": {
    "checkUserPassword": null
  },
  "extensions": {
    "tracing": {
      "version": 1,
      "startTime": "2021-08-08T11:56:40.4614177Z",
      "endTime": "2021-08-08T11:56:40.4616358Z",
      "duration": 218200,
      "execution": {
        "resolvers": [
          {
            "path": [
              "checkUserPassword"
            ],
            "parentType": "Query",
            "fieldName": "checkUserPassword",
            "returnType": "User",
            "startOffset": 95900,
            "duration": 87200,
            "dgraph": [
              {
                "label": "query",
                "startOffset": 0,
                "duration": 0
              }
            ]
          }
        ]
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![pshaddel](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/pshaddel/32/11584_2.png) [@pshaddel](https://discuss.dgraph.io/u/pshaddel)\
**Post date:** [August 8, 2021, 1:28pm UTC](https://discuss.dgraph.io/t/check-password-query-is-rewritten-into-invalid-dql-query/15234/2 "2021-08-08T13:28:05Z")

</div>

Hello @hastri and welcome,  
I’m not sure about the reason but I was able to get the expected result with this token without using :  
`eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJleHAiOjE2NTExMTExMTEsInN1YiI6IiIsInVzZXIiOiJIRUxMTyJ9.6q2SUgrnfy-1zoYgdKq7ueI3wU6Tpj7IpQI43RpxT1A`  
This is the payload:  
`{ "exp": 1651111111, "sub": "", "user": "HELLO" }`

---

<div class="post-metadata">

**Author:** ![hastri](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/hastri/32/8697_2.png) [@hastri](https://discuss.dgraph.io/u/hastri)\
**Post date:** [August 8, 2021, 1:32pm UTC](https://discuss.dgraph.io/t/check-password-query-is-rewritten-into-invalid-dql-query/15234/3 "2021-08-08T13:32:01Z")

</div>

That’s probably because the domain.user property is missing and the rule is therefore not even checked

---

<div class="post-metadata">

**Author:** ![pshaddel](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/pshaddel/32/11584_2.png) [@pshaddel](https://discuss.dgraph.io/u/pshaddel)\
**Post date:** [August 8, 2021, 1:40pm UTC](https://discuss.dgraph.io/t/check-password-query-is-rewritten-into-invalid-dql-query/15234/4 "2021-08-08T13:40:23Z")

</div>

I checked what you said and it is working:  
First I added a role with name: `HELLO`  
This is the result with this token that I have a role named: `HELLO`:  
`eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJleHAiOjE2NTExMTExMTEsInN1YiI6IiIsIlVTRVIiOiJIRUxMTyJ9.PoY-jkGUbrWm7aqVcfCyikQf5NCsfnZMyZNwTepBou4`

 ![Screen Shot 2021-08-08 at 6.06.17 PM](https://canada1.discourse-cdn.com/flex007/uploads/dgraph/original/2X/c/c6682887ce531932b1ee44486fcc54192fc23f77.png)

And this is the result of sending request with token that user is `BYE`:  
`eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJleHAiOjE2NTExMTExMTEsInN1YiI6IiIsIlVTRVIiOiJCWUUifQ.tal8VmXHt6DkKN9Cd6vIC2UIII5k9MijdqMTjcEd8B4`

 ![Screen Shot 2021-08-08 at 6.08.10 PM](https://canada1.discourse-cdn.com/flex007/uploads/dgraph/original/2X/1/1784074ac318cc93e5b15cef075d5c0794ebc84e.png)
