{"record":{"id":"ec9a441bd44f8ce6","repo":"influxdata/influxdb","slug":"token-info-must-be-present-after-token-creation-by-name","errorCode":null,"errorMessage":"token info must be present after token creation by name","messagePattern":"token info must be present after token creation by name","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"influxdb3_catalog/src/catalog/versions/v1/enterprise.rs","lineNumber":118,"sourceCode":"                        token_id,\n                        name: Arc::from(token_name.as_str()),\n                        hash: hash.clone(),\n                        created_at,\n                        expiry,\n                        permissions: all_perms,\n                    },\n                )],\n            }))\n        })\n        .await?;\n\n        let token_info = {\n            self.inner\n                .read()\n                .tokens\n                .repo()\n                .get_by_name(&token_name)\n                .expect(\"token info must be present after token creation by name\")\n        };\n\n        // we need to pass these details back, especially this token as this is what user should\n        // send in subsequent requests\n        Ok((token_info, token))\n    }\n}\n\nimpl InnerCatalog {\n    pub fn apply_token_batch_enterprise(&mut self, token_batch: &TokenBatch) -> Result<bool> {\n        let mut is_updated = false;\n        for op in &token_batch.ops {\n            is_updated |= match op {\n                TokenCatalogOp::CreateAdminToken(create_admin_token_details) => {\n                    // add an entry into permissions\n                    self.token_permissions.add_permission(\n                        ResourceType::Wildcard,\n                        TokenPermissionResourceIdentifier::Wildcard,","sourceCodeStart":100,"sourceCodeEnd":136,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_catalog/src/catalog/versions/v1/enterprise.rs#L100-L136","documentation":"A `.expect(...)` panic right after enterprise token creation: the code writes the token, then re-reads it by name from the token repo and asserts it exists. If the read returns None, the write and subsequent read are inconsistent — an internal invariant failure (concurrent delete, name collision handling, or write not committed).","triggerScenarios":"Calling `create_token_with_permission` when the just-created token cannot be found by name on the immediate `get_by_name` lookup — e.g. another thread deleted/renamed it between the write and the read, or the write silently failed to insert under the expected name.","commonSituations":"Concurrent token management (one thread creating while another lists/deletes tokens); a bug in the write path (wrong name stored); unusual token names (empty, unicode) that don't round-trip through `get_by_name`.","solutions":["Check for concurrent token deletion/rename races and serialize token-management operations.","Verify the name used at creation matches the name used in `get_by_name` exactly (case, whitespace, encoding).","Re-run the operation; if reproducible single-threaded, it is a library bug — report it with the token name and catalog version.","Replace the `expect` with an error return (e.g. internal error) so callers get a recoverable failure instead of a panic."],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"// panic, not catchable as an error; wrap the whole creation in catch_unwind and retry once\nlet res = std::panic::catch_unwind(|| create_token_with_permission(...));\nif res.is_err() { retry_with_backoff_or_report_bug(); }","preventionTips":["Serialize token create/delete/rename operations (single writer or lock) to avoid read-back races.","Use plain ASCII token names without whitespace or case tricks.","After any panic here, verify catalog state for partially created tokens before retrying.","Report reproducible single-threaded failures to InfluxData — this is an internal invariant."],"tags":["influxdb3","auth","token","panic","race-condition","rust"],"backgroundTag":"internal-invariant-violation","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}