{"record":{"id":"78fba57057e01d50","repo":"influxdata/influxdb","slug":"unimplemented","errorCode":null,"errorMessage":"unimplemented","messagePattern":"unimplemented","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"influxdb3_authz/src/authorizer.rs","lineNumber":164,"sourceCode":"                            let required = role::role_permissions::RolePermission::new(action);\n                            permissions.has_permission(&required)\n                        }\n                    },\n                    AccessRequest::AdminToken(action) => {\n                        let required = role::role_permissions::AdminTokenPermission::new(action);\n                        permissions.has_permission(&required)\n                    }\n                    AccessRequest::ResourceToken(action) => {\n                        let required = role::role_permissions::TokenPermission::new(action);\n                        permissions.has_permission(&required)\n                    }\n                    AccessRequest::System(resource_id, actions) => {\n                        check_user_system_access(permissions, resource_id, actions)\n                    }\n                    AccessRequest::AnyDatabase(actions) => {\n                        check_user_database_access(permissions, None, actions)\n                    }\n                    AccessRequest::Token(_token_id, _crud_actions) => unimplemented!(),\n                };\n                if authorized {\n                    Ok(())\n                } else {\n                    Err(ResourceAuthorizationError::Unauthorized)\n                }\n            }\n        }\n    }\n\n    fn should_check_token(&self) -> bool {\n        true\n    }\n\n    fn upcast(&self) -> Arc<dyn IoxAuthorizer> {\n        let cloned_self = (*self).clone();\n        Arc::new(cloned_self) as _\n    }","sourceCodeStart":146,"sourceCodeEnd":182,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/authorizer.rs#L146-L182","documentation":"This is a Rust `unimplemented!()` panic raised inside `authorize_action` in influxdb3_authz when an access request targets a Token resource. Token-level CRUD authorization was never implemented in this authorizer; the code path is a deliberate placeholder. Hitting it means a request asked the authorizer to check permissions on a specific token, which the current implementation cannot do.","triggerScenarios":"An AccessRequest::Token(token_id, crud_actions) is dispatched during authorization, e.g. an API flow that manages/inspects tokens through the authorizer; also reproduced directly in tests like test_authorizer_authorization_failed and role_authoring_* tests.","commonSituations":"Developers wiring new token-management endpoints into the authz layer; enabling permission paths that enumerate per-token CRUD actions that were never supported.","solutions":["Do not route token-level authorization through this authorizer; implement an explicit AccessRequest::Token arm with real permission checks","Handle/authorize token management at a higher layer (e.g. admin-only gate) before reaching authorize_action","If you maintain the crate, replace unimplemented!() with a proper ResourceAuthorizationError variant"],"exampleFix":"// before\nAccessRequest::Token(_token_id, _crud_actions) => unimplemented!(),\n// after\nAccessRequest::Token(token_id, crud_actions) =>\n    check_user_token_access(permissions, token_id, crud_actions),","handlingStrategy":"type-guard","validationCode":null,"typeGuard":"fn is_token_request(req: &AccessRequest) -> bool {\n    matches!(req, AccessRequest::Token(_, _))\n}\n// skip/redirect authorization when is_token_request(&req) is true","tryCatchPattern":null,"preventionTips":["Never route token-management requests through authorize_action","Guard new AccessRequest variants with explicit handling before merging","Add tests covering every AccessRequest variant to catch panics early"],"tags":["rust","panic","unimplemented","authorization"],"backgroundTag":"method-not-implemented","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}