influxdata/influxdb · error · ResourceMappingError

resource type not supported

Error message

resource type not supported {0}

What it means

ResourceMappingError::ResourceTypeNotSupported is thrown when a resource type string passed to the permission resource-mapping layer cannot be mapped to a known resource type. The authz crate maintains a fixed set of recognized resource types; any other string is rejected. It indicates the caller supplied a resource type outside the supported vocabulary.

Solutions

  1. Check the resource type string against the ResourceType definitions in influxdb3_authz/src/permissions.rs and correct the typo.
  2. Upgrade or align the influxdb3_authz crate version so both sides of the permission data agree on supported resource types.
  3. If a genuinely new resource type is needed, extend the ResourceType enum and its FromStr/mapping implementation.

Example fix

// before
let rt = "buckets"; // unsupported
// after
let rt = "databases"; // a supported ResourceType string
Defensive patterns

Strategy: validation

Validate before calling

const SUPPORTED: &[&str] = &["databases", "tables", "tokens", "system"];
fn is_supported_resource_type(rt: &str) -> bool { SUPPORTED.contains(&rt) || rt == "*" }

Try / catch

match map_resource_type(rt) {
    Ok(id) => id,
    Err(ResourceMappingError::ResourceTypeNotSupported(s)) => bail!("unsupported resource type: {s}"),
    Err(e) => return Err(e.into()),
}

Prevention

When it happens

Trigger: Calling permission/resource mapping APIs (e.g. converting a resource name/type string into a resource identifier) with a resource-type string that is not one of the recognized influxdb3 resource types.

Common situations: Typo in a resource type in token permission definitions; using a resource type from an older or newer InfluxDB 3 version that the current crate version does not know; hand-editing serialized permission JSON.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/a2943d849e4fbea7. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/permissions.rs:32

pub const AUTHZ_TOKEN_RESOURCE_TYPE: &str = "token";

pub const AUTHZ_CREATE_DB_ACTION: &str = "create";
pub const AUTHZ_DESCRIBE_DB_ACTION: &str = "describe";
pub const AUTHZ_WRITE_DB_ACTION: &str = "write";
pub const AUTHZ_READ_DB_ACTION: &str = "read";

pub const AUTHZ_DELETE_ROW_ACTION: &str = "delete";

pub const AUTHZ_CREATE_CRUD_ACTION: &str = "create";
pub const AUTHZ_READ_CRUD_ACTION: &str = "read";
pub const AUTHZ_UPDATE_CRUD_ACTION: &str = "update";
pub const AUTHZ_DELETE_CRUD_ACTION: &str = "delete";

pub const AUTHZ_WILDCARD: &str = "*";

#[derive(Debug, Error)]
pub enum ResourceMappingError {
    #[error("resource type not supported {0}")]
    ResourceTypeNotSupported(String),
    #[error("invalid resource name {0}")]
    InvalidResourceName(String),
    #[error("mixed wildcard (*) and resource name")]
    MixedWildcardAndRegularResourceName,
    #[error("missing resource name {0}")]
    MissingResourceName(String),
    #[error("action not supported, {0}")]
    ActionNotSupported(String),
    #[error("missing resource id {0}")]
    MissingResourceId(String),
}

pub trait ResourceNameToIdProvider {
    fn resource_name_to_id(
        &self,
        resource_type: ResourceType,
        names: &[String],

View on GitHub (pinned to 06200ef96b)