{"record":{"id":"c8b279d221490fbc","repo":"influxdata/influxdb","slug":"mixed-wildcard-and-resource-name","errorCode":null,"errorMessage":"mixed wildcard (*) and resource name","messagePattern":"mixed wildcard \\(\\*\\) and resource name","errorType":"error_code","errorClass":"ResourceMappingError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/permissions.rs","lineNumber":36,"sourceCode":"pub const AUTHZ_WRITE_DB_ACTION: &str = \"write\";\npub const AUTHZ_READ_DB_ACTION: &str = \"read\";\n\npub const AUTHZ_DELETE_ROW_ACTION: &str = \"delete\";\n\npub const AUTHZ_CREATE_CRUD_ACTION: &str = \"create\";\npub const AUTHZ_READ_CRUD_ACTION: &str = \"read\";\npub const AUTHZ_UPDATE_CRUD_ACTION: &str = \"update\";\npub const AUTHZ_DELETE_CRUD_ACTION: &str = \"delete\";\n\npub const AUTHZ_WILDCARD: &str = \"*\";\n\n#[derive(Debug, Error)]\npub enum ResourceMappingError {\n    #[error(\"resource type not supported {0}\")]\n    ResourceTypeNotSupported(String),\n    #[error(\"invalid resource name {0}\")]\n    InvalidResourceName(String),\n    #[error(\"mixed wildcard (*) and resource name\")]\n    MixedWildcardAndRegularResourceName,\n    #[error(\"missing resource name {0}\")]\n    MissingResourceName(String),\n    #[error(\"action not supported, {0}\")]\n    ActionNotSupported(String),\n    #[error(\"missing resource id {0}\")]\n    MissingResourceId(String),\n}\n\npub trait ResourceNameToIdProvider {\n    fn resource_name_to_id(\n        &self,\n        resource_type: ResourceType,\n        names: &[String],\n    ) -> Result<ResourceIdentifier, ResourceMappingError>;\n}\n\npub trait ResourceIdToNameProvider {","sourceCodeStart":18,"sourceCodeEnd":54,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/permissions.rs#L18-L54","documentation":"ResourceMappingError::MixedWildcardAndRegularResourceName is thrown when a set of resources mixes the wildcard \"*\" with concrete resource names. Permissions are either wildcard (all resources) or enumerated (specific names), never both, so the mapping layer rejects such input outright.","triggerScenarios":"Constructing a resource permission from a list of resource names where one entry is \"*\" and at least one other entry is a concrete resource name.","commonSituations":"Merging permission lists from multiple config sources where one contains \"*\"; appending a specific resource to an existing wildcard permission without deduplication.","solutions":["Remove the wildcard \"*\" and enumerate all intended resource names, or","Keep only the wildcard \"*\" if access to every resource of the type is intended.","Add preprocessing that collapses any list containing \"*\" into a single wildcard permission."],"exampleFix":"// before\nlet names = vec![\"*\", \"my_db\"];\n// after\nlet names = vec![\"*\"]; // or vec![\"my_db\"]","handlingStrategy":"validation","validationCode":"fn collapse_wildcards(names: &[&str]) -> Option<Vec<&str>> {\n    if names.contains(&\"*\") { Some(vec![\"*\"]) } else { Some(names.to_vec()) }\n}","typeGuard":null,"tryCatchPattern":"let names = collapse_wildcards(&raw_names).ok_or_else(|| anyhow!(\"mixed wildcard and names\"))?;","preventionTips":["Treat \"*\" as terminal: if present, ignore all other entries","Normalize/merge permission lists centrally before passing them to the authz API","Test permission merging logic with wildcard-containing inputs"],"tags":["authz","permissions","wildcard"],"backgroundTag":"conflicting-config-options","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}