influxdata/influxdb · error · ResourceMappingError

action not supported

Error message

action not supported, {0}

What it means

ResourceMappingError::ActionNotSupported is thrown when an action string supplied for a permission is not one the authz layer recognizes. Valid actions are the CRUD-style constants (e.g. "create", "read", "update", "delete") defined in permissions.rs; anything else is rejected.

Solutions

  1. Check the action string against the AUTHZ_*_CRUD_ACTION constants and the ADMIN_ACTIONS set in permissions.rs.
  2. Use the wildcard action "*" if all actions are intended.
  3. Align the client/config version with the influxdb3_authz version that defines the actions used.

Example fix

// before
let actions = vec!["write"]; // unsupported
// after
let actions = vec!["create", "read", "update", "delete"];
Defensive patterns

Strategy: validation

Validate before calling

const ACTIONS: &[&str] = &["*", "create", "read", "update", "delete"];
fn is_valid_action(a: &str) -> bool { ACTIONS.contains(&a) }

Try / catch

match map_action(a) {
    Ok(bit) => bit,
    Err(ResourceMappingError::ActionNotSupported(s)) => bail!("unsupported action: {s}"),
    Err(e) => return Err(e.into()),
}

Prevention

When it happens

Trigger: Building or parsing token permissions with an action string that is not among the AUTHZ_*_CRUD_ACTION constants (or the wildcard "*").

Common situations: Typos like "read_all" or "write" where the API expects "read"/"update"; using action names from another authorization system; version drift adding actions not present in this crate version.

Understand the failure class

Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/236484dab771584f. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/permissions.rs:40

pub const AUTHZ_CREATE_CRUD_ACTION: &str = "create";
pub const AUTHZ_READ_CRUD_ACTION: &str = "read";
pub const AUTHZ_UPDATE_CRUD_ACTION: &str = "update";
pub const AUTHZ_DELETE_CRUD_ACTION: &str = "delete";

pub const AUTHZ_WILDCARD: &str = "*";

#[derive(Debug, Error)]
pub enum ResourceMappingError {
    #[error("resource type not supported {0}")]
    ResourceTypeNotSupported(String),
    #[error("invalid resource name {0}")]
    InvalidResourceName(String),
    #[error("mixed wildcard (*) and resource name")]
    MixedWildcardAndRegularResourceName,
    #[error("missing resource name {0}")]
    MissingResourceName(String),
    #[error("action not supported, {0}")]
    ActionNotSupported(String),
    #[error("missing resource id {0}")]
    MissingResourceId(String),
}

pub trait ResourceNameToIdProvider {
    fn resource_name_to_id(
        &self,
        resource_type: ResourceType,
        names: &[String],
    ) -> Result<ResourceIdentifier, ResourceMappingError>;
}

pub trait ResourceIdToNameProvider {
    fn resource_id_to_name(
        &self,
        identifier: &ResourceIdentifier,
    ) -> Vec<Result<String, ResourceMappingError>>;

View on GitHub (pinned to 06200ef96b)