influxdata/influxdb · error · ResourceAuthorizationError
resource type not supported
Error message
resource type not supported, {0} What it means
ResourceAuthorizationError::ResourceNotSupported is produced when the authorizer is asked to authorize an action against a resource type it does not understand. The unknown resource type is embedded in the message. It signals a mismatch between the API layer's resource model and what the authz crate supports.
Solutions
- Upgrade influxdb3_authz / the server so both sides know the resource type
- Check the resource type string passed into the authorization request for mistakes
- Add a match arm for the new resource type in the authorizer if you maintain the crate
Example fix
// before: unknown resource kind passed through authorize(Resource::Bucket(name), action) // after: use a supported resource type authorize(Resource::Database(name), action)
Defensive patterns
Strategy: type-guard
Type guard
fn is_unsupported_resource(err: &ResourceAuthorizationError) -> bool {
matches!(err, ResourceAuthorizationError::ResourceNotSupported(_))
} Try / catch
match authorize(req) {
Err(ResourceAuthorizationError::ResourceNotSupported(t)) => {
log::warn!("authz does not support resource type: {t}");
// fail closed or upgrade path
}
other => other?,
} Prevention
- Keep the authz crate and API resource model in lockstep (upgrade together)
- Centralize resource-type construction so no ad-hoc types appear
- Add an exhaustive match with a compile-time exhaustiveness check
When it happens
Trigger: An authorization request carries a resource variant/type string that ResourceAuthorization does not map to (e.g. a newly added resource kind not yet handled in the authorizer's match arms).
Common situations: Version skew where a newer server/API introduces a resource type the authz crate predates; plugin or custom code constructing authorization requests with ad-hoc resource types.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- unauthorized to perform requested action with the token
- ' ' is a reserved column
- Authorization error
- authorization failure
- auto field family exists
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/7ce0e55cd23389bf.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/lib.rs:72
pub enum AccessRequest {
MaybeDatabase(Option<DbId>, DatabaseActions),
Database(DbId, DatabaseActions),
AnyDatabase(DatabaseActions),
Token(TokenId, CrudActions),
System(SystemResourceIdentifier, SystemActions),
User(role::UserAction),
Role(role::RoleAction),
AdminToken(role::AdminTokenAction),
ResourceToken(role::TokenAction),
Admin,
}
#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
#[error("unauthorized to perform requested action with the token")]
Unauthorized,
#[error("resource type not supported, {0}")]
ResourceNotSupported(String),
}
#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
/// Error for token that is present in the request but missing in the catalog
#[error("token provided is not present in catalog")]
InvalidToken,
/// Error for token that has expired
#[error("token has expired {0}")]
ExpiredToken(String),
/// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
#[error("missing token to authenticate")]
MissingToken,
/// Error for invalid JWT (bad signature, malformed, etc.)
#[error("invalid JWT")]
InvalidJwt,
/// Error for expired JWTView on GitHub (pinned to 06200ef96b)