{"record":{"id":"d5b20e78916131db","repo":"influxdata/influxdb","slug":"token-hash-already-exists","errorCode":null,"errorMessage":"token hash already exists","messagePattern":"token hash already exists","errorType":"error_code","errorClass":"CatalogError","httpStatus":null,"severity":"error","filePath":"influxdb3_catalog/src/error.rs","lineNumber":285,"sourceCode":"    #[error(\"last cache size must be greater than 0\")]\n    InvalidLastCacheSize,\n\n    #[error(\"failed to parse trigger from {trigger_spec}{}\", .context.as_ref().map(|context| format!(\": {context}\")).unwrap_or_default())]\n    TriggerSpecificationParseError {\n        trigger_spec: String,\n        context: Option<String>,\n    },\n\n    #[error(\"invalid error behavior {0}\")]\n    InvalidErrorBehavior(String),\n\n    #[error(\"cannot parse token permission, {0}\")]\n    CannotParsePermissionForToken(String),\n\n    #[error(\"token name already exists, {0}\")]\n    TokenNameAlreadyExists(String),\n\n    #[error(\"token hash already exists\")]\n    TokenHashAlreadyExists,\n\n    #[error(\"missing admin token, cannot update\")]\n    MissingAdminTokenToUpdate,\n\n    #[error(\"cannot delete internal db\")]\n    CannotDeleteInternalDatabase,\n\n    #[error(\"cannot modify internal db\")]\n    CannotModifyInternalDatabase,\n\n    #[error(\"tried to stop a node ({node_id}) that is already stopped\")]\n    NodeAlreadyStopped { node_id: Arc<str> },\n\n    #[error(\n        \"node '{node_id}' is not fully stopped (current state: {current_state}); run \\\"stop node\\\" first\"\n    )]\n    NodeNotFullyStopped {","sourceCodeStart":267,"sourceCodeEnd":303,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_catalog/src/error.rs#L267-L303","documentation":"This error is thrown when the hash of a token being created already exists in the catalog. Token hashes must be unique because they are the lookup key for authenticating requests; a duplicate hash indicates the same token secret was generated (or reused) twice.","triggerScenarios":"Creating a token whose generated hash collides with an existing token hash — practically, retrying token creation with the same pre-shared token string, or catalog data containing duplicated token hashes.","commonSituations":"Importing/restoring catalogs where token rows were duplicated; deterministic token generation in scripts producing the same secret; replaying a token-creation request against a restored catalog.","solutions":["Generate a fresh token secret instead of reusing an existing one","Check the catalog for the duplicate token entry and remove the stale one","If restoring from backup, deduplicate tokens before import","Retry the operation — cryptographic hash collisions from fresh random secrets are effectively impossible"],"exampleFix":"// before\nlet token = \"influxdb3_token_fixed\"; // reused secret\ncreate_token_with_secret(token)?;\n// after\nlet token = generate_random_token(); // fresh secret each run\ncreate_token_with_secret(&token)?;","handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"match create_token_with_secret(secret) {\n    Err(CatalogError::TokenHashAlreadyExists) => retry_with_fresh_secret(),\n    r => r,\n}","preventionTips":["Always generate token secrets with a CSPRNG, never hardcode","Deduplicate tokens when restoring/importing catalogs","Don't replay token-creation requests with the same secret"],"tags":["catalog","auth","tokens","uniqueness"],"backgroundTag":"file-already-exists","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}