influxdata/influxdb · error · NewRoleNameError

role name contains invalid characters: only alphanumeric and

Error message

role name contains invalid characters: only alphanumeric and [{0}] are allowed

What it means

NewRoleNameError::InvalidCharacters is returned when a role name contains characters outside the allowed set: alphanumeric characters plus the characters listed in the error's payload (formatted by format_allowed_chars). The library rejects such names to keep role identifiers safe in URLs and identifiers.

Solutions

  1. Sanitize the name to only alphanumeric characters (and the allowed punctuation listed in the error message, typically '-' and '_')
  2. Replace disallowed characters with '-' or '_' before submitting
  3. Add client-side validation with a regex like ^[a-zA-Z0-9_-]+$ before calling the API

Example fix

// before
let name = "platform/eng admin";
// after
let name = "platform-eng-admin"; // or sanitize: input.chars().map(|c| if c.is_ascii_alphanumeric() || ALLOWED.contains(&c) { c } else { '-' }).collect()
Defensive patterns

Strategy: validation

Validate before calling

fn valid_role_name_chars(name: &str) -> bool {
    // allowed extras (e.g. '-' and '_') come from format_allowed_chars in role.rs
    name.chars().all(|c| c.is_ascii_alphanumeric() || c == '-' || c == '_')
}

Type guard

fn sanitize_role_name(raw: &str) -> String {
    raw.chars().map(|c| if c.is_ascii_alphanumeric() || c == '-' || c == '_' { c } else { '-' }).collect()
}

Prevention

When it happens

Trigger: Passing a role name containing spaces, symbols (e.g. '/', '@', ':'), or non-ASCII characters to role creation or renaming APIs.

Common situations: Deriving role names from user emails, URLs, or display labels ('Platform Eng admins') that contain spaces or punctuation.

Understand the failure class

Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/13d8398f201b5b34. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/role/role.rs:92

    pub fn into_inner(self) -> String {
        self.0
    }
}

impl std::fmt::Display for RoleName {
    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
        write!(f, "{}", self.0)
    }
}

#[derive(Debug, Clone, Error)]
pub enum NewRoleNameError {
    #[error("role name cannot be empty")]
    Empty,
    #[error("role name exceeds maximum length of {ROLE_NAME_MAX_LENGTH} characters")]
    TooLong,
    #[error("role name contains invalid characters: only alphanumeric and [{0}] are allowed")]
    InvalidCharacters(String),
}

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct RoleDescription(String);

impl RoleDescription {
    pub fn as_str(&self) -> &str {
        &self.0
    }

    pub fn new(description: &str) -> Result<Self, NewRoleDescriptionError> {
        if description.is_empty() {
            return Err(NewRoleDescriptionError::Empty);
        }

        if description.len() > ROLE_DESCRIPTION_MAX_LENGTH {
            return Err(NewRoleDescriptionError::TooLong);

View on GitHub (pinned to 06200ef96b)