{"record":{"id":"236484dab771584f","repo":"influxdata/influxdb","slug":"action-not-supported-0","errorCode":null,"errorMessage":"action not supported, {0}","messagePattern":"action not supported, (.+?)","errorType":"error_code","errorClass":"ResourceMappingError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/permissions.rs","lineNumber":40,"sourceCode":"\npub const AUTHZ_CREATE_CRUD_ACTION: &str = \"create\";\npub const AUTHZ_READ_CRUD_ACTION: &str = \"read\";\npub const AUTHZ_UPDATE_CRUD_ACTION: &str = \"update\";\npub const AUTHZ_DELETE_CRUD_ACTION: &str = \"delete\";\n\npub const AUTHZ_WILDCARD: &str = \"*\";\n\n#[derive(Debug, Error)]\npub enum ResourceMappingError {\n    #[error(\"resource type not supported {0}\")]\n    ResourceTypeNotSupported(String),\n    #[error(\"invalid resource name {0}\")]\n    InvalidResourceName(String),\n    #[error(\"mixed wildcard (*) and resource name\")]\n    MixedWildcardAndRegularResourceName,\n    #[error(\"missing resource name {0}\")]\n    MissingResourceName(String),\n    #[error(\"action not supported, {0}\")]\n    ActionNotSupported(String),\n    #[error(\"missing resource id {0}\")]\n    MissingResourceId(String),\n}\n\npub trait ResourceNameToIdProvider {\n    fn resource_name_to_id(\n        &self,\n        resource_type: ResourceType,\n        names: &[String],\n    ) -> Result<ResourceIdentifier, ResourceMappingError>;\n}\n\npub trait ResourceIdToNameProvider {\n    fn resource_id_to_name(\n        &self,\n        identifier: &ResourceIdentifier,\n    ) -> Vec<Result<String, ResourceMappingError>>;","sourceCodeStart":22,"sourceCodeEnd":58,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/permissions.rs#L22-L58","documentation":"ResourceMappingError::ActionNotSupported is thrown when an action string supplied for a permission is not one the authz layer recognizes. Valid actions are the CRUD-style constants (e.g. \"create\", \"read\", \"update\", \"delete\") defined in permissions.rs; anything else is rejected.","triggerScenarios":"Building or parsing token permissions with an action string that is not among the AUTHZ_*_CRUD_ACTION constants (or the wildcard \"*\").","commonSituations":"Typos like \"read_all\" or \"write\" where the API expects \"read\"/\"update\"; using action names from another authorization system; version drift adding actions not present in this crate version.","solutions":["Check the action string against the AUTHZ_*_CRUD_ACTION constants and the ADMIN_ACTIONS set in permissions.rs.","Use the wildcard action \"*\" if all actions are intended.","Align the client/config version with the influxdb3_authz version that defines the actions used."],"exampleFix":"// before\nlet actions = vec![\"write\"]; // unsupported\n// after\nlet actions = vec![\"create\", \"read\", \"update\", \"delete\"];","handlingStrategy":"validation","validationCode":"const ACTIONS: &[&str] = &[\"*\", \"create\", \"read\", \"update\", \"delete\"];\nfn is_valid_action(a: &str) -> bool { ACTIONS.contains(&a) }","typeGuard":null,"tryCatchPattern":"match map_action(a) {\n    Ok(bit) => bit,\n    Err(ResourceMappingError::ActionNotSupported(s)) => bail!(\"unsupported action: {s}\"),\n    Err(e) => return Err(e.into()),\n}","preventionTips":["Reference the AUTHZ_*_CRUD_ACTION constants instead of literal strings","Share an action enum between config producers and this crate","Document valid actions where tokens/permissions are authored"],"tags":["authz","permissions","actions"],"backgroundTag":"invalid-enum-value","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}