{"record":{"id":"1d30a70a7421a75a","repo":"apache/iceberg","slug":"malformed-request-s-s","errorCode":null,"errorMessage":"Malformed request: %s: %s","messagePattern":"Malformed request: (.+?): (.+?)","errorType":"exception","errorClass":"BadRequestException","httpStatus":400,"severity":"error","filePath":"core/src/main/java/org/apache/iceberg/rest/ErrorHandlers.java","lineNumber":386,"sourceCode":"      } catch (Exception x) {\n        LOG.warn(\"Unable to parse error response\", x);\n      }\n      return ErrorResponse.builder().responseCode(code).withMessage(json).build();\n    }\n\n    @Override\n    public void accept(ErrorResponse error) {\n      if (error.type() != null) {\n        switch (error.type()) {\n          case OAuth2Properties.INVALID_CLIENT_ERROR:\n            throw new NotAuthorizedException(\n                \"Not authorized: %s: %s\", error.type(), error.message());\n          case OAuth2Properties.INVALID_REQUEST_ERROR:\n          case OAuth2Properties.INVALID_GRANT_ERROR:\n          case OAuth2Properties.UNAUTHORIZED_CLIENT_ERROR:\n          case OAuth2Properties.UNSUPPORTED_GRANT_TYPE_ERROR:\n          case OAuth2Properties.INVALID_SCOPE_ERROR:\n            throw new BadRequestException(\n                \"Malformed request: %s: %s\", error.type(), error.message());\n        }\n      }\n      throw createRESTException(error);\n    }\n  }\n}\n","sourceCodeStart":368,"sourceCodeEnd":394,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/core/src/main/java/org/apache/iceberg/rest/ErrorHandlers.java#L368-L394","documentation":"The OAuth2 error handler maps OAuth token endpoint errors of types invalid_request, invalid_grant, unauthorized_client, unsupported_grant_type, and invalid_scope to BadRequestException. The token request itself was malformed or used unsupported/granted-disallowed parameters per RFC 6749.","triggerScenarios":"Token exchange returned HTTP 400 with one of the five handled OAuth error types — e.g. requesting an unsupported grant type (client_credentials not enabled), requesting scopes the client is not authorized for, or a malformed token request.","commonSituations":"Requesting 'scope' values the auth server doesn't recognize, auth server not supporting client_credentials grant, misplaced Audience/Resource parameters sent as scope, or an incompatible OAuth2 server implementation.","solutions":["Check the server description in the message; it names the offending parameter","Remove or correct the 'scope' catalog property if the requested scope isn't supported","Verify your OAuth2 server supports the grant type being used (client_credentials)","Ensure you're hitting a spec-compliant token endpoint at oauth2-server-uri"],"exampleFix":"// before\nprops.put(\"oauth2-server-uri\", \"https://auth.example.com/authorize\"); // wrong endpoint\nprops.put(\"scope\", \"all_the_things\");\n// after\nprops.put(\"oauth2-server-uri\", \"https://auth.example.com/token\");\n// remove unsupported scope","handlingStrategy":"validation","validationCode":"String scope = props.get(\"scope\");\nif (scope != null && !supportedScopes.contains(scope)) {\n  throw new IllegalArgumentException(\"Unsupported OAuth2 scope: \" + scope);\n}","typeGuard":null,"tryCatchPattern":"try {\n  String token = OAuth2Util.fetchToken(client, authConfig);\n} catch (BadRequestException e) {\n  throw new IllegalStateException(\"Token request rejected: \" + e.getMessage(), e);\n}","preventionTips":["Only request scopes documented by your OAuth2 server","Confirm the token endpoint supports client_credentials grant","Point oauth2-server-uri at the token endpoint, not the authorize endpoint"],"tags":["rest","oauth2","token-exchange","bad-request"],"backgroundTag":"oauth-token-exchange-failed","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}