{"record":{"id":"7ce0e55cd23389bf","repo":"influxdata/influxdb","slug":"resource-type-not-supported-0","errorCode":null,"errorMessage":"resource type not supported, {0}","messagePattern":"resource type not supported, (.+?)","errorType":"error_code","errorClass":"ResourceAuthorizationError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/lib.rs","lineNumber":72,"sourceCode":"pub enum AccessRequest {\n    MaybeDatabase(Option<DbId>, DatabaseActions),\n    Database(DbId, DatabaseActions),\n    AnyDatabase(DatabaseActions),\n    Token(TokenId, CrudActions),\n    System(SystemResourceIdentifier, SystemActions),\n    User(role::UserAction),\n    Role(role::RoleAction),\n    AdminToken(role::AdminTokenAction),\n    ResourceToken(role::TokenAction),\n    Admin,\n}\n\n#[derive(Debug, Clone, thiserror::Error)]\npub enum ResourceAuthorizationError {\n    #[error(\"unauthorized to perform requested action with the token\")]\n    Unauthorized,\n\n    #[error(\"resource type not supported, {0}\")]\n    ResourceNotSupported(String),\n}\n\n#[derive(Debug, thiserror::Error)]\npub enum AuthenticatorError {\n    /// Error for token that is present in the request but missing in the catalog\n    #[error(\"token provided is not present in catalog\")]\n    InvalidToken,\n    /// Error for token that has expired\n    #[error(\"token has expired {0}\")]\n    ExpiredToken(String),\n    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)\n    #[error(\"missing token to authenticate\")]\n    MissingToken,\n    /// Error for invalid JWT (bad signature, malformed, etc.)\n    #[error(\"invalid JWT\")]\n    InvalidJwt,\n    /// Error for expired JWT","sourceCodeStart":54,"sourceCodeEnd":90,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/lib.rs#L54-L90","documentation":"ResourceAuthorizationError::ResourceNotSupported is produced when the authorizer is asked to authorize an action against a resource type it does not understand. The unknown resource type is embedded in the message. It signals a mismatch between the API layer's resource model and what the authz crate supports.","triggerScenarios":"An authorization request carries a resource variant/type string that ResourceAuthorization does not map to (e.g. a newly added resource kind not yet handled in the authorizer's match arms).","commonSituations":"Version skew where a newer server/API introduces a resource type the authz crate predates; plugin or custom code constructing authorization requests with ad-hoc resource types.","solutions":["Upgrade influxdb3_authz / the server so both sides know the resource type","Check the resource type string passed into the authorization request for mistakes","Add a match arm for the new resource type in the authorizer if you maintain the crate"],"exampleFix":"// before: unknown resource kind passed through\nauthorize(Resource::Bucket(name), action)\n// after: use a supported resource type\nauthorize(Resource::Database(name), action)","handlingStrategy":"type-guard","validationCode":null,"typeGuard":"fn is_unsupported_resource(err: &ResourceAuthorizationError) -> bool {\n    matches!(err, ResourceAuthorizationError::ResourceNotSupported(_))\n}","tryCatchPattern":"match authorize(req) {\n    Err(ResourceAuthorizationError::ResourceNotSupported(t)) => {\n        log::warn!(\"authz does not support resource type: {t}\");\n        // fail closed or upgrade path\n    }\n    other => other?,\n}","preventionTips":["Keep the authz crate and API resource model in lockstep (upgrade together)","Centralize resource-type construction so no ad-hoc types appear","Add an exhaustive match with a compile-time exhaustiveness check"],"tags":["authorization","unsupported-resource","influxdb3"],"backgroundTag":"unsupported-operation","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}