{"record":{"id":"48b559c15b6a72b7","repo":"influxdata/influxdb","slug":"cannot-parse-token-permission-0","errorCode":null,"errorMessage":"cannot parse token permission, {0}","messagePattern":"cannot parse token permission, (.+?)","errorType":"error_code","errorClass":"CatalogError","httpStatus":null,"severity":"error","filePath":"influxdb3_catalog/src/error.rs","lineNumber":279,"sourceCode":"        trigger_name: String,\n    },\n\n    #[error(\"failed to parse trigger from {}\", trigger_spec)]\n    ProcessingEngineTriggerSpecParseError { trigger_spec: String },\n\n    #[error(\"last cache size must be greater than 0\")]\n    InvalidLastCacheSize,\n\n    #[error(\"failed to parse trigger from {trigger_spec}{}\", .context.as_ref().map(|context| format!(\": {context}\")).unwrap_or_default())]\n    TriggerSpecificationParseError {\n        trigger_spec: String,\n        context: Option<String>,\n    },\n\n    #[error(\"invalid error behavior {0}\")]\n    InvalidErrorBehavior(String),\n\n    #[error(\"cannot parse token permission, {0}\")]\n    CannotParsePermissionForToken(String),\n\n    #[error(\"token name already exists, {0}\")]\n    TokenNameAlreadyExists(String),\n\n    #[error(\"token hash already exists\")]\n    TokenHashAlreadyExists,\n\n    #[error(\"missing admin token, cannot update\")]\n    MissingAdminTokenToUpdate,\n\n    #[error(\"cannot delete internal db\")]\n    CannotDeleteInternalDatabase,\n\n    #[error(\"cannot modify internal db\")]\n    CannotModifyInternalDatabase,\n\n    #[error(\"tried to stop a node ({node_id}) that is already stopped\")]","sourceCodeStart":261,"sourceCodeEnd":297,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_catalog/src/error.rs#L261-L297","documentation":"This error occurs when a permission string attached to a token cannot be parsed into a catalog permission. The token permissions are stored as strings and deserialized into the `Permission` type; an unrecognized or malformed permission string triggers this error with the bad value in the message.","triggerScenarios":"Creating or updating an API token whose permission list contains a string that does not match any known permission; loading a catalog file that contains hand-edited or legacy permission strings.","commonSituations":"Hand-editing the catalog/Neo4j-style stored token definitions; copying permission names from older InfluxDB versions; typos like `read:buckets` vs the InfluxDB 3 permission naming scheme.","solutions":["Use only documented permission names for the token (e.g. via the influxdb3 CLI token creation flags)","Inspect the message for the offending permission string and correct it","If migrating from an old catalog, regenerate tokens rather than copying permission strings","Upgrade/re-sync the catalog if the permission scheme changed between versions"],"exampleFix":"// before\nTokenInfo::new(\"my-token\", &[\"read:bucket:mydb\"]);\n// after\nTokenInfo::new(\"my-token\", &[\"read:buckets\"]);\n// use the Permission enum / documented permission strings","handlingStrategy":"validation","validationCode":"fn permissions_parse(ps: &[&str]) -> Result<(), String> {\n    ps.iter().map(|p| p.parse::<Permission>())\n      .collect::<Result<Vec<_>, _>>().map(|_| ()).map_err(|e| e.to_string())\n}","typeGuard":null,"tryCatchPattern":"match result {\n    Err(CatalogError::CannotParsePermissionForToken(p)) => eprintln!(\"fix permission string: {p}\"),\n    r => r,\n}","preventionTips":["Construct permissions via the `Permission` type rather than raw strings","Never hand-edit catalog token data","Validate permission strings against docs for your InfluxDB 3 version"],"tags":["catalog","auth","tokens","permissions","parsing"],"backgroundTag":"invalid-enum-value","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}