{"record":{"id":"cc6cf3450e8f3541","repo":"influxdata/influxdb","slug":"requestor-is-forbidden-from-requested-resource","errorCode":null,"errorMessage":"requestor is forbidden from requested resource","messagePattern":"requestor is forbidden from requested resource","errorType":"http","errorClass":"AuthenticationError","httpStatus":403,"severity":"error","filePath":"influxdb3_server/src/http.rs","lineNumber":406,"sourceCode":"    #[error(\"Current node mode does not use the processing engine\")]\n    NoProcessingEngine,\n\n    #[error(\"invalid request: {0}\")]\n    InvalidRequest(String),\n\n    #[error(transparent)]\n    LegacyWriteParse(#[from] WriteParseError),\n}\n\n#[derive(Debug, Error)]\npub(crate) enum AuthenticationError {\n    #[error(\"the request was not authenticated\")]\n    Unauthenticated,\n    #[error(\n        \"Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic\"\n    )]\n    MalformedRequest,\n    #[error(\"requestor is forbidden from requested resource\")]\n    Forbidden,\n    #[error(\"to str error: {0}\")]\n    ToStr(#[from] hyper::header::ToStrError),\n}\n\nimpl IntoResponse for AuthenticationError {\n    fn into_response(self) -> Response {\n        let code = match self {\n            Self::Unauthenticated => StatusCode::UNAUTHORIZED,\n            Self::MalformedRequest => StatusCode::BAD_REQUEST,\n            Self::Forbidden => StatusCode::FORBIDDEN,\n            Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,\n        };\n\n        ResponseBuilder::new()\n            .status(code)\n            .body(bytes_to_response_body(format!(r#\"{{\"error\": \"{self}\"}}\"#)))\n            .unwrap()","sourceCodeStart":388,"sourceCodeEnd":424,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_server/src/http.rs#L388-L424","documentation":"Variant `Forbidden` of `AuthenticationError` in influxdb3_server/src/http.rs. The requestor presented valid credentials but is not permitted to access the requested resource, so the server rejects the call with a forbidden response.","triggerScenarios":"Using a token that lacks the required permissions for the target database/resource (e.g. a read-only token against a write endpoint, or a token scoped to another database).","commonSituations":"Tokens issued for a different environment/instance; least-privilege tokens used by services that later need write access; copying a token from a colleague with narrower permissions; expiring or rotated tokens no longer mapped to sufficient privileges.","solutions":["Create a token with the required permissions (e.g. `influxdb3 create token --permissions 'write:db/mydb'`) and use it instead","Confirm the token's permission set covers the endpoint and database being called","Point the client at a database the token is actually authorized for"],"exampleFix":"// before: read-only token used for writes\n// after: issue a token with write permission\ninfluxdb3 create token --permissions 'write:db/mydb' --expiry '30d'\ncurl -H 'Authorization: Bearer <new_token>' -X POST 'host/api/v3/write?db=mydb' --data 'm v=1'","handlingStrategy":"validation","validationCode":"// Verify token permissions cover the target before calling\nasync function assertCanWrite(host, token, db) {\n  const res = await fetch(`${host}/api/v3/write?db=${db}`, {method: 'HEAD', headers: {Authorization: `Bearer ${token}`}});\n  if (res.status === 403) throw new Error(`token lacks write permission for ${db}`);\n}","typeGuard":null,"tryCatchPattern":"try {\n  return await api.write(data);\n} catch (e) {\n  if (e.status === 403 || String(e.message).includes('forbidden')) {\n    throw new PermissionError('token lacks required permissions; issue a token with write scope');\n  }\n  throw e;\n}","preventionTips":["Match token permission scope (read/write, database) to the service's actual needs","Re-issue tokens when service responsibilities change"],"tags":["http","authorization","permissions","forbidden"],"backgroundTag":"permission-denied","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}