influxdata/influxdb · error · ResourceMappingError

mixed wildcard (*) and resource name

Error message

mixed wildcard (*) and resource name

What it means

ResourceMappingError::MixedWildcardAndRegularResourceName is thrown when a set of resources mixes the wildcard "*" with concrete resource names. Permissions are either wildcard (all resources) or enumerated (specific names), never both, so the mapping layer rejects such input outright.

Solutions

  1. Remove the wildcard "*" and enumerate all intended resource names, or
  2. Keep only the wildcard "*" if access to every resource of the type is intended.
  3. Add preprocessing that collapses any list containing "*" into a single wildcard permission.

Example fix

// before
let names = vec!["*", "my_db"];
// after
let names = vec!["*"]; // or vec!["my_db"]
Defensive patterns

Strategy: validation

Validate before calling

fn collapse_wildcards(names: &[&str]) -> Option<Vec<&str>> {
    if names.contains(&"*") { Some(vec!["*"]) } else { Some(names.to_vec()) }
}

Try / catch

let names = collapse_wildcards(&raw_names).ok_or_else(|| anyhow!("mixed wildcard and names"))?;

Prevention

When it happens

Trigger: Constructing a resource permission from a list of resource names where one entry is "*" and at least one other entry is a concrete resource name.

Common situations: Merging permission lists from multiple config sources where one contains "*"; appending a specific resource to an existing wildcard permission without deduplication.

Understand the failure class

Background: Conflicting config options: "cannot be used together" — configuration validation errors across open-source libraries — this error's family across 162 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/c8b279d221490fbc. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/permissions.rs:36

pub const AUTHZ_WRITE_DB_ACTION: &str = "write";
pub const AUTHZ_READ_DB_ACTION: &str = "read";

pub const AUTHZ_DELETE_ROW_ACTION: &str = "delete";

pub const AUTHZ_CREATE_CRUD_ACTION: &str = "create";
pub const AUTHZ_READ_CRUD_ACTION: &str = "read";
pub const AUTHZ_UPDATE_CRUD_ACTION: &str = "update";
pub const AUTHZ_DELETE_CRUD_ACTION: &str = "delete";

pub const AUTHZ_WILDCARD: &str = "*";

#[derive(Debug, Error)]
pub enum ResourceMappingError {
    #[error("resource type not supported {0}")]
    ResourceTypeNotSupported(String),
    #[error("invalid resource name {0}")]
    InvalidResourceName(String),
    #[error("mixed wildcard (*) and resource name")]
    MixedWildcardAndRegularResourceName,
    #[error("missing resource name {0}")]
    MissingResourceName(String),
    #[error("action not supported, {0}")]
    ActionNotSupported(String),
    #[error("missing resource id {0}")]
    MissingResourceId(String),
}

pub trait ResourceNameToIdProvider {
    fn resource_name_to_id(
        &self,
        resource_type: ResourceType,
        names: &[String],
    ) -> Result<ResourceIdentifier, ResourceMappingError>;
}

pub trait ResourceIdToNameProvider {

View on GitHub (pinned to 06200ef96b)