influxdata/influxdb · error · ResourceMappingError
mixed wildcard (*) and resource name
Error message
mixed wildcard (*) and resource name
What it means
ResourceMappingError::MixedWildcardAndRegularResourceName is thrown when a set of resources mixes the wildcard "*" with concrete resource names. Permissions are either wildcard (all resources) or enumerated (specific names), never both, so the mapping layer rejects such input outright.
Solutions
- Remove the wildcard "*" and enumerate all intended resource names, or
- Keep only the wildcard "*" if access to every resource of the type is intended.
- Add preprocessing that collapses any list containing "*" into a single wildcard permission.
Example fix
// before let names = vec!["*", "my_db"]; // after let names = vec!["*"]; // or vec!["my_db"]
Defensive patterns
Strategy: validation
Validate before calling
fn collapse_wildcards(names: &[&str]) -> Option<Vec<&str>> {
if names.contains(&"*") { Some(vec!["*"]) } else { Some(names.to_vec()) }
} Try / catch
let names = collapse_wildcards(&raw_names).ok_or_else(|| anyhow!("mixed wildcard and names"))?; Prevention
- Treat "*" as terminal: if present, ignore all other entries
- Normalize/merge permission lists centrally before passing them to the authz API
- Test permission merging logic with wildcard-containing inputs
When it happens
Trigger: Constructing a resource permission from a list of resource names where one entry is "*" and at least one other entry is a concrete resource name.
Common situations: Merging permission lists from multiple config sources where one contains "*"; appending a specific resource to an existing wildcard permission without deduplication.
Understand the failure class
Background: Conflicting config options: "cannot be used together" — configuration validation errors across open-source libraries — this error's family across 162 libraries.
Related errors
- action not supported
- invalid resource name
- missing resource id
- missing resource name
- resource type not supported
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/c8b279d221490fbc.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/permissions.rs:36
pub const AUTHZ_WRITE_DB_ACTION: &str = "write";
pub const AUTHZ_READ_DB_ACTION: &str = "read";
pub const AUTHZ_DELETE_ROW_ACTION: &str = "delete";
pub const AUTHZ_CREATE_CRUD_ACTION: &str = "create";
pub const AUTHZ_READ_CRUD_ACTION: &str = "read";
pub const AUTHZ_UPDATE_CRUD_ACTION: &str = "update";
pub const AUTHZ_DELETE_CRUD_ACTION: &str = "delete";
pub const AUTHZ_WILDCARD: &str = "*";
#[derive(Debug, Error)]
pub enum ResourceMappingError {
#[error("resource type not supported {0}")]
ResourceTypeNotSupported(String),
#[error("invalid resource name {0}")]
InvalidResourceName(String),
#[error("mixed wildcard (*) and resource name")]
MixedWildcardAndRegularResourceName,
#[error("missing resource name {0}")]
MissingResourceName(String),
#[error("action not supported, {0}")]
ActionNotSupported(String),
#[error("missing resource id {0}")]
MissingResourceId(String),
}
pub trait ResourceNameToIdProvider {
fn resource_name_to_id(
&self,
resource_type: ResourceType,
names: &[String],
) -> Result<ResourceIdentifier, ResourceMappingError>;
}
pub trait ResourceIdToNameProvider {View on GitHub (pinned to 06200ef96b)