influxdata/influxdb · error
resource type should be parseable
Error message
resource type should be parseable
What it means
A `.expect(...)` panic in the enterprise token batch handler: each requested permission's `resource_type` string is parsed with `ResourceType::from_str` and asserted to succeed. The comment acknowledges validation 'should' have happened earlier, so any unparseable resource type reaching this point panics instead of returning an error.
Solutions
- Fix the `resource_type` string in the permission request to a valid value (e.g. exactly as ResourceType's FromStr expects, correct case, no whitespace).
- Validate permissions against the ResourceType enum's accepted strings before submitting the token-creation batch.
- Align client and server versions so their permission vocabularies match.
- If you control the code, propagate the parse error instead of `expect`-panicking (per the referenced issue influxdb_pro#745).
Example fix
// before
.expect("resource type should be parseable");
// after
let resource_type = ResourceType::from_str(&permission.resource_type)
.map_err(|e| anyhow!("invalid resource_type '{}': {e}", permission.resource_type))?; Defensive patterns
Strategy: validation
Validate before calling
// validate every permission before calling the batch handler
const VALID: &[&str] = &["telegraf", "database", "bucket", ...]; // match ResourceType::from_str
for p in &permissions {
if ResourceType::from_str(&p.resource_type).is_err() {
return Err(anyhow!("unsupported resource_type: '{}'", p.resource_type));
}
} Type guard
fn is_valid_resource_type(s: &str) -> bool {
ResourceType::from_str(s).is_ok()
} Try / catch
// this is a panic; pre-filter the permission list before apply_token_batch_enterprise let perms: Vec<_> = permissions.into_iter().filter(|p| is_valid_resource_type(&p.resource_type)).collect();
Prevention
- Copy resource_type strings from the server's own ResourceType enum, never free-typed.
- Trim and case-normalize resource_type strings at the API boundary.
- Keep client SDK versions in sync with server permission vocabulary.
- Add an allow-list validator for permission payloads in your tooling.
When it happens
Trigger: Calling `handle_token_creation` (via `apply_token_batch_enterprise`) with a `create_token_details.permissions` entry whose `resource_type` string is not a known ResourceType (e.g. "buckets ", "buckets_extra", different casing, or a new resource type unknown to this build).
Common situations: Client sending permissions authored against a newer/older InfluxDB version whose resource-type vocabulary differs; typos or whitespace/case mismatches in resource_type; enterprise/cloud tooling generating permission lists not valid for OSS-style ResourceType parsing.
Understand the failure class
Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.
Related errors
- duration not to overflow
- token info must be present after token creation by name
- column id in series key should be valid
- generation duration overflows u64 nanoseconds
- row_delete_predicate_version exceeds u64
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/ebdf6581aade6003.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_catalog/src/catalog/versions/v1/enterprise.rs:182
fn handle_token_creation(
&mut self,
create_token_details: &CreateTokenDetails,
) -> Result<(), crate::CatalogError> {
let mut token_info = TokenInfo::new(
create_token_details.token_id,
Arc::clone(&create_token_details.name),
create_token_details.hash.clone(),
create_token_details.created_at,
create_token_details.expiry,
);
let mut all_permissions = Vec::new();
// NB: the validation has already happened when coming to this point so it's safe
// ignore the errors here and use `expect`. This will be tidied up when addressing
// issue, https://github.com/influxdata/influxdb_pro/issues/745
for permission in &create_token_details.permissions {
let resource_type = ResourceType::from_str(&permission.resource_type)
.expect("resource type should be parseable");
let allowed_actions =
Actions::build_actions_for_type(resource_type, &permission.actions)
.expect("resource actions to be parseable");
let resource_identifier = {
let name_to_id_provider =
Arc::from(self.clone()) as Arc<dyn ResourceNameToIdProvider>;
ResourceIdentifier::build_resource_ids_for_type(
resource_type,
name_to_id_provider,
&permission.resource_identifier,
)
.expect("resource identifier to be parseable")
};
match resource_identifier {
ResourceIdentifier::Database(ref db_ids) => {
for db_id in db_ids {View on GitHub (pinned to 06200ef96b)