{"record":{"id":"3f9065672afe1830","repo":"influxdata/influxdb","slug":"unauthorized-to-perform-requested-action-with-the-token","errorCode":null,"errorMessage":"unauthorized to perform requested action with the token","messagePattern":"unauthorized to perform requested action with the token","errorType":"error_code","errorClass":"ResourceAuthorizationError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/lib.rs","lineNumber":69,"sourceCode":"}\n\n#[derive(Debug, Clone, Copy, PartialEq)]\npub enum AccessRequest {\n    MaybeDatabase(Option<DbId>, DatabaseActions),\n    Database(DbId, DatabaseActions),\n    AnyDatabase(DatabaseActions),\n    Token(TokenId, CrudActions),\n    System(SystemResourceIdentifier, SystemActions),\n    User(role::UserAction),\n    Role(role::RoleAction),\n    AdminToken(role::AdminTokenAction),\n    ResourceToken(role::TokenAction),\n    Admin,\n}\n\n#[derive(Debug, Clone, thiserror::Error)]\npub enum ResourceAuthorizationError {\n    #[error(\"unauthorized to perform requested action with the token\")]\n    Unauthorized,\n\n    #[error(\"resource type not supported, {0}\")]\n    ResourceNotSupported(String),\n}\n\n#[derive(Debug, thiserror::Error)]\npub enum AuthenticatorError {\n    /// Error for token that is present in the request but missing in the catalog\n    #[error(\"token provided is not present in catalog\")]\n    InvalidToken,\n    /// Error for token that has expired\n    #[error(\"token has expired {0}\")]\n    ExpiredToken(String),\n    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)\n    #[error(\"missing token to authenticate\")]\n    MissingToken,\n    /// Error for invalid JWT (bad signature, malformed, etc.)","sourceCodeStart":51,"sourceCodeEnd":87,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/lib.rs#L51-L87","documentation":"ResourceAuthorizationError::Unauthorized is returned by the influxdb3_authz authorizer when the authenticated principal's permissions do not cover the requested action on the resource. Unlike an authentication failure, the caller was identified but lacks entitlement. authorize_action converts any failed permission check into this error.","triggerScenarios":"A token/user attempts a database or system action (read/write/create) whose required permission is absent from its permission set; e.g. a read-only token attempting a write, or a non-admin using an admin-only role action.","commonSituations":"Using a token scoped to one database against another; tokens created before a permission scheme change; attempting admin-only operations with a regular user.","solutions":["Issue a new token with the required permissions for the target resource","Verify the token maps to the intended permission set in the catalog","Use an admin credential for admin-only actions","Check you are targeting the database the token was scoped to"],"exampleFix":"// before: read-only token used for a write\nlet client = Client::new(url, None, false)?.with_auth_token(&read_only_token);\n// after: use a token with write permission on the database\nlet client = Client::new(url, None, false)?.with_auth_token(&write_token);","handlingStrategy":"try-catch","validationCode":null,"typeGuard":"fn is_unauthorized(err: &IoxError) -> bool {\n    err.to_string().contains(\"unauthorized to perform requested action with the token\")\n}","tryCatchPattern":"match authorizer.authorize(...).await {\n    Ok(()) => proceed(),\n    Err(e) if matches!(e, ResourceAuthorizationError::Unauthorized) => {\n        return status::Forbidden; // 403, not 401\n    }\n    Err(e) => return Err(e.into()),\n}","preventionTips":["Issue tokens with the exact permissions the workload needs","Audit permission sets after auth scheme changes","Use admin credentials only for admin operations","Keep a test that exercises each token's permitted actions"],"tags":["authorization","permissions","token","influxdb3"],"backgroundTag":"insufficient-permissions","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}