influxdata/influxdb · error · ResourceMappingError

invalid resource name

Error message

invalid resource name {0}

What it means

ResourceMappingError::InvalidResourceName is thrown when a resource name string fails validation during conversion from a name to a resource identifier. The name is syntactically or semantically invalid for the permission mapping layer, distinct from a name that simply does not resolve.

Solutions

  1. Validate the resource name spelling and formatting against expected resource naming (alphanumeric/identifier rules).
  2. Use the wildcard "*" explicitly if all resources of the type are intended, rather than a made-up name.
  3. Log/inspect the offending string in the error payload and correct it in the permission configuration.

Example fix

// before
let perm = resource_name("db 1 main"); // invalid
// after
let perm = resource_name("db1_main");
Defensive patterns

Strategy: validation

Validate before calling

fn is_valid_resource_name(name: &str) -> bool {
    !name.is_empty() && name.chars().all(|c| c.is_alphanumeric() || c == '_' || c == '-')
}

Try / catch

match map_resource_name(name) {
    Ok(id) => id,
    Err(ResourceMappingError::InvalidResourceName(n)) => bail!("invalid resource name: {n}"),
    Err(e) => return Err(e.into()),
}

Prevention

When it happens

Trigger: Passing a malformed resource name to the ResourceNameToIdProvider-based mapping functions used when constructing token permissions.

Common situations: Hand-written permission specs with misspelled resource names; whitespace or stray characters in configured resource names; copying names from another InfluxDB edition with a different naming scheme.

Understand the failure class

Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/a8c87f51c4232470. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/permissions.rs:34

pub const AUTHZ_CREATE_DB_ACTION: &str = "create";
pub const AUTHZ_DESCRIBE_DB_ACTION: &str = "describe";
pub const AUTHZ_WRITE_DB_ACTION: &str = "write";
pub const AUTHZ_READ_DB_ACTION: &str = "read";

pub const AUTHZ_DELETE_ROW_ACTION: &str = "delete";

pub const AUTHZ_CREATE_CRUD_ACTION: &str = "create";
pub const AUTHZ_READ_CRUD_ACTION: &str = "read";
pub const AUTHZ_UPDATE_CRUD_ACTION: &str = "update";
pub const AUTHZ_DELETE_CRUD_ACTION: &str = "delete";

pub const AUTHZ_WILDCARD: &str = "*";

#[derive(Debug, Error)]
pub enum ResourceMappingError {
    #[error("resource type not supported {0}")]
    ResourceTypeNotSupported(String),
    #[error("invalid resource name {0}")]
    InvalidResourceName(String),
    #[error("mixed wildcard (*) and resource name")]
    MixedWildcardAndRegularResourceName,
    #[error("missing resource name {0}")]
    MissingResourceName(String),
    #[error("action not supported, {0}")]
    ActionNotSupported(String),
    #[error("missing resource id {0}")]
    MissingResourceId(String),
}

pub trait ResourceNameToIdProvider {
    fn resource_name_to_id(
        &self,
        resource_type: ResourceType,
        names: &[String],
    ) -> Result<ResourceIdentifier, ResourceMappingError>;
}

View on GitHub (pinned to 06200ef96b)