{"record":{"id":"ebdf6581aade6003","repo":"influxdata/influxdb","slug":"resource-type-should-be-parseable","errorCode":null,"errorMessage":"resource type should be parseable","messagePattern":"resource type should be parseable","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"influxdb3_catalog/src/catalog/versions/v1/enterprise.rs","lineNumber":182,"sourceCode":"\n    fn handle_token_creation(\n        &mut self,\n        create_token_details: &CreateTokenDetails,\n    ) -> Result<(), crate::CatalogError> {\n        let mut token_info = TokenInfo::new(\n            create_token_details.token_id,\n            Arc::clone(&create_token_details.name),\n            create_token_details.hash.clone(),\n            create_token_details.created_at,\n            create_token_details.expiry,\n        );\n        let mut all_permissions = Vec::new();\n        // NB: the validation has already happened when coming to this point so it's safe\n        //     ignore the errors here and use `expect`. This will be tidied up when addressing\n        //     issue, https://github.com/influxdata/influxdb_pro/issues/745\n        for permission in &create_token_details.permissions {\n            let resource_type = ResourceType::from_str(&permission.resource_type)\n                .expect(\"resource type should be parseable\");\n            let allowed_actions =\n                Actions::build_actions_for_type(resource_type, &permission.actions)\n                    .expect(\"resource actions to be parseable\");\n\n            let resource_identifier = {\n                let name_to_id_provider =\n                    Arc::from(self.clone()) as Arc<dyn ResourceNameToIdProvider>;\n                ResourceIdentifier::build_resource_ids_for_type(\n                    resource_type,\n                    name_to_id_provider,\n                    &permission.resource_identifier,\n                )\n                .expect(\"resource identifier to be parseable\")\n            };\n\n            match resource_identifier {\n                ResourceIdentifier::Database(ref db_ids) => {\n                    for db_id in db_ids {","sourceCodeStart":164,"sourceCodeEnd":200,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_catalog/src/catalog/versions/v1/enterprise.rs#L164-L200","documentation":"A `.expect(...)` panic in the enterprise token batch handler: each requested permission's `resource_type` string is parsed with `ResourceType::from_str` and asserted to succeed. The comment acknowledges validation 'should' have happened earlier, so any unparseable resource type reaching this point panics instead of returning an error.","triggerScenarios":"Calling `handle_token_creation` (via `apply_token_batch_enterprise`) with a `create_token_details.permissions` entry whose `resource_type` string is not a known ResourceType (e.g. \"buckets \", \"buckets_extra\", different casing, or a new resource type unknown to this build).","commonSituations":"Client sending permissions authored against a newer/older InfluxDB version whose resource-type vocabulary differs; typos or whitespace/case mismatches in resource_type; enterprise/cloud tooling generating permission lists not valid for OSS-style ResourceType parsing.","solutions":["Fix the `resource_type` string in the permission request to a valid value (e.g. exactly as ResourceType's FromStr expects, correct case, no whitespace).","Validate permissions against the ResourceType enum's accepted strings before submitting the token-creation batch.","Align client and server versions so their permission vocabularies match.","If you control the code, propagate the parse error instead of `expect`-panicking (per the referenced issue influxdb_pro#745)."],"exampleFix":"// before\n.expect(\"resource type should be parseable\");\n// after\nlet resource_type = ResourceType::from_str(&permission.resource_type)\n    .map_err(|e| anyhow!(\"invalid resource_type '{}': {e}\", permission.resource_type))?;","handlingStrategy":"validation","validationCode":"// validate every permission before calling the batch handler\nconst VALID: &[&str] = &[\"telegraf\", \"database\", \"bucket\", ...]; // match ResourceType::from_str\nfor p in &permissions {\n    if ResourceType::from_str(&p.resource_type).is_err() {\n        return Err(anyhow!(\"unsupported resource_type: '{}'\", p.resource_type));\n    }\n}","typeGuard":"fn is_valid_resource_type(s: &str) -> bool {\n    ResourceType::from_str(s).is_ok()\n}","tryCatchPattern":"// this is a panic; pre-filter the permission list before apply_token_batch_enterprise\nlet perms: Vec<_> = permissions.into_iter().filter(|p| is_valid_resource_type(&p.resource_type)).collect();","preventionTips":["Copy resource_type strings from the server's own ResourceType enum, never free-typed.","Trim and case-normalize resource_type strings at the API boundary.","Keep client SDK versions in sync with server permission vocabulary.","Add an allow-list validator for permission payloads in your tooling."],"tags":["influxdb3","auth","permissions","panic","rust"],"backgroundTag":"invalid-enum-value","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}