influxdata/influxdb · error · ResourceMappingError
action not supported
Error message
action not supported, {0} What it means
ResourceMappingError::ActionNotSupported is thrown when an action string supplied for a permission is not one the authz layer recognizes. Valid actions are the CRUD-style constants (e.g. "create", "read", "update", "delete") defined in permissions.rs; anything else is rejected.
Solutions
- Check the action string against the AUTHZ_*_CRUD_ACTION constants and the ADMIN_ACTIONS set in permissions.rs.
- Use the wildcard action "*" if all actions are intended.
- Align the client/config version with the influxdb3_authz version that defines the actions used.
Example fix
// before let actions = vec!["write"]; // unsupported // after let actions = vec!["create", "read", "update", "delete"];
Defensive patterns
Strategy: validation
Validate before calling
const ACTIONS: &[&str] = &["*", "create", "read", "update", "delete"];
fn is_valid_action(a: &str) -> bool { ACTIONS.contains(&a) } Try / catch
match map_action(a) {
Ok(bit) => bit,
Err(ResourceMappingError::ActionNotSupported(s)) => bail!("unsupported action: {s}"),
Err(e) => return Err(e.into()),
} Prevention
- Reference the AUTHZ_*_CRUD_ACTION constants instead of literal strings
- Share an action enum between config producers and this crate
- Document valid actions where tokens/permissions are authored
When it happens
Trigger: Building or parsing token permissions with an action string that is not among the AUTHZ_*_CRUD_ACTION constants (or the wildcard "*").
Common situations: Typos like "read_all" or "write" where the API expects "read"/"update"; using action names from another authorization system; version drift adding actions not present in this crate version.
Understand the failure class
Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.
Related errors
- invalid resource name
- missing resource id
- missing resource name
- mixed wildcard (*) and resource name
- resource type not supported
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/236484dab771584f.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/permissions.rs:40
pub const AUTHZ_CREATE_CRUD_ACTION: &str = "create";
pub const AUTHZ_READ_CRUD_ACTION: &str = "read";
pub const AUTHZ_UPDATE_CRUD_ACTION: &str = "update";
pub const AUTHZ_DELETE_CRUD_ACTION: &str = "delete";
pub const AUTHZ_WILDCARD: &str = "*";
#[derive(Debug, Error)]
pub enum ResourceMappingError {
#[error("resource type not supported {0}")]
ResourceTypeNotSupported(String),
#[error("invalid resource name {0}")]
InvalidResourceName(String),
#[error("mixed wildcard (*) and resource name")]
MixedWildcardAndRegularResourceName,
#[error("missing resource name {0}")]
MissingResourceName(String),
#[error("action not supported, {0}")]
ActionNotSupported(String),
#[error("missing resource id {0}")]
MissingResourceId(String),
}
pub trait ResourceNameToIdProvider {
fn resource_name_to_id(
&self,
resource_type: ResourceType,
names: &[String],
) -> Result<ResourceIdentifier, ResourceMappingError>;
}
pub trait ResourceIdToNameProvider {
fn resource_id_to_name(
&self,
identifier: &ResourceIdentifier,
) -> Vec<Result<String, ResourceMappingError>>;View on GitHub (pinned to 06200ef96b)