{"record":{"id":"589ea2cc8ac8288c","repo":"influxdata/influxdb","slug":"authorization-error-0","errorCode":null,"errorMessage":"Authorization error: {0}","messagePattern":"Authorization error: (.+?)","errorType":"http","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"influxdb3_server/src/http.rs","lineNumber":367,"sourceCode":"    #[error(\"heap dump failed: {0}\")]\n    HeapPprof(#[from] jemalloc_pprof_http::Error),\n\n    #[error(transparent)]\n    Catalog(#[from] CatalogError),\n\n    #[error(\"Python plugins not enabled on this server\")]\n    PythonPluginsNotEnabled,\n\n    #[error(\"Plugin error: {0}\")]\n    Plugin(#[from] influxdb3_processing_engine::plugins::PluginError),\n\n    #[error(\"Processing engine error: {0}\")]\n    ProcessingEngine(#[from] influxdb3_processing_engine::manager::ProcessingEngineError),\n\n    #[error(transparent)]\n    Influxdb3TypesHttp(#[from] influxdb3_types::http::Error),\n\n    #[error(\"Authorization error: {0}\")]\n    ResourceAuthorization(#[from] ResourceAuthorizationError),\n\n    #[error(\"Authentication error: {0}\")]\n    Authentication(#[from] AuthenticatorError),\n\n    #[error(\"The following Database does not exist: {0}\")]\n    MissingDb(String),\n\n    #[error(\"The following Database Table does not exist: {0}\")]\n    MissingTable(String),\n\n    #[error(\"Cannot parse the given human time: {0}\")]\n    ParsingHumanTime(#[source] humantime::DurationError),\n\n    #[error(\"Cannot parse the timestamp: {0}\")]\n    ParsingTimestamp(#[from] chrono::ParseError),\n\n    #[error(\"Timestamp is out of range\")]","sourceCodeStart":349,"sourceCodeEnd":385,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_server/src/http.rs#L349-L385","documentation":"Wraps `ResourceAuthorizationError` via `#[from]` into the server HTTP error enum. The request was authenticated (the caller's identity is known) but that identity is not permitted to perform the requested action on the resource — e.g. read/write permission missing, or the action isn't allowed on that database/token. The inner message names the denied resource/action.","triggerScenarios":"Any HTTP API call whose token lacks the required permission: querying a database the token cannot read, writing to a restricted database, using an admin-only endpoint (e.g. processing-engine configuration) with a read-only token, or a token from another resource/tenant.","commonSituations":"Using a token created with too-narrow permissions; pointing a client at the wrong database; rotating tokens and shipping an old scope; calling admin endpoints with an operator-vs-read token mix-up.","solutions":["Inspect the inner ResourceAuthorizationError to see which action/resource was denied.","Create or update the token with the required permissions (e.g. write access to the target database) and update the client's `Authorization: Bearer` header.","Confirm the request targets the database/resource the token is scoped to.","If multi-tenant, verify you are using a token issued for the correct account/tenant."],"exampleFix":"// before\n// curl -H \"Authorization: Bearer <read-only-token>\" .../api/v3/write?db=metrics\n// after: mint a token with write access to db 'metrics' and use it","handlingStrategy":"validation","validationCode":"// Verify token permissions before the call\nconst auth = await api.me(token);\nconst canWrite = auth.permissions.some(p => p.action === 'write' && p.resource.db === 'metrics');\nif (!canWrite) throw new Error(`token lacks write permission on db 'metrics'`);","typeGuard":null,"tryCatchPattern":"try {\n  await api.write(db, points);\n} catch (e) {\n  if (/Authorization error:/.test(e.message)) {\n    throw new PermissionError(`Token not allowed to write ${db}: ${e.message}`);\n  }\n  throw e;\n}","preventionTips":["Provision tokens with explicit, minimal-but-sufficient permissions per database","Store the target database in config next to the token so scopes stay matched","Audit and rotate tokens on a schedule; propagate new tokens to all clients"],"tags":["authorization","permissions","auth","http-api"],"backgroundTag":"permission-denied","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}