{"record":{"id":"c520400d8a2fc19a","repo":"influxdata/influxdb","slug":"authorization-failure-0","errorCode":null,"errorMessage":"authorization failure: {0}","messagePattern":"authorization failure: (.+?)","errorType":"http","errorClass":"Error::AuthorizationFailure","httpStatus":null,"severity":"error","filePath":"core/iox_v1_query_api/src/error.rs","lineNumber":22,"sourceCode":"use iox_query_influxql_rewrite as rewrite;\nuse thiserror::Error;\n\n/// Error type for the v1 API\n///\n/// This is used to catch errors that occur during the streaming process.\n/// [`anyhow::Error`] is used as a catch-all because if anything fails during\n/// that process it will result in a 500 INTERNAL ERROR.\n#[derive(Debug, thiserror::Error)]\n#[error(\"unexpected query error: {0}\")]\npub struct QueryError(#[from] pub anyhow::Error);\n\n#[derive(Debug, Error)]\npub enum Error {\n    /// The requested path has no registered handler.\n    #[error(\"not found: {0}\")]\n    NoHandler(String),\n\n    #[error(\"authorization failure: {0}\")]\n    AuthorizationFailure(String),\n\n    #[error(\"invalid mime type ({0})\")]\n    InvalidMimeType(String),\n\n    /// Missing parameters for query\n    #[error(\"missing query parameters 'db' and 'q'\")]\n    MissingQueryParams,\n\n    #[error(\"error decoding multipart file upload: {0}\")]\n    MultipartFile(String),\n\n    #[error(\"Invalid UTF8: {message} {error}\")]\n    Utf8 {\n        message: &'static str,\n        error: String,\n    },\n","sourceCodeStart":4,"sourceCodeEnd":40,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/core/iox_v1_query_api/src/error.rs#L4-L40","documentation":"`Error::AuthorizationFailure(String)` signals that the request failed authorization in the v1 query API. The handler rejects the request because the supplied credentials/authorizations do not permit the operation, with details in the message.","triggerScenarios":"Calling the v1 query API with a missing, malformed, or insufficient Authorization header/token for the requested database or operation.","commonSituations":"Expired or rotated tokens still deployed in clients, tokens lacking read permission on the target bucket/database, or sending credentials to a server configured with different auth expectations.","solutions":["Verify the Authorization header is present and correctly formatted (e.g. `Token <token>` scheme).","Check the token's permissions include read access to the target database/bucket.","Regenerate/rotate the token and update the client configuration."],"exampleFix":"// before\nlet resp = client.get(\"/query\").send().await?;\n// after\nlet resp = client.get(\"/query\")\n    .header(\"Authorization\", format!(\"Token {}\", read_token))\n    .send().await?;","handlingStrategy":"type-guard","validationCode":null,"typeGuard":"fn is_auth_failure(e: &iox_v1_query_api::Error) -> bool {\n    matches!(e, iox_v1_query_api::Error::AuthorizationFailure(_))\n}","tryCatchPattern":"match api.query(&token, sql).await {\n    Err(e) if is_auth_failure(&e) => {\n        refresh_token();\n        retry_once(sql)\n    }\n    other => other,\n}","preventionTips":["Check token expiry/permissions programmatically before long-running jobs.","Store tokens in config/secret managers with rotation handling, not hardcoded values.","Grant the token only the scopes it needs, and verify the scope list after creation."],"tags":["rust","http-api","authorization","auth","thiserror"],"backgroundTag":"permission-denied","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}