influxdata/influxdb · error · NewRoleNameError

role name exceeds maximum length of

Error message

role name exceeds maximum length of {ROLE_NAME_MAX_LENGTH} characters

What it means

NewRoleNameError::TooLong is returned when validating a role name that is longer than ROLE_NAME_MAX_LENGTH characters. The role system enforces a name length cap so role identifiers stay usable in HTTP APIs, catalogs, and logs. Validation happens when constructing a new RoleName via its TryFrom/constructor path.

Solutions

  1. Shorten the role name to at most ROLE_NAME_MAX_LENGTH characters and retry
  2. Check the limit at compile/source time (constant ROLE_NAME_MAX_LENGTH in influxdb3_authz/src/role/role.rs) and validate input length before calling the API
  3. If generating names programmatically, truncate or hash long components while keeping them unique

Example fix

// before
let name = format!("role-for-{}-{}", long_team_name, environment); // may exceed limit
// after
let name: String = format!("role-{}-{}", truncate(&long_team_name, 32), environment)
    .chars().take(ROLE_NAME_MAX_LENGTH).collect();
Defensive patterns

Strategy: validation

Validate before calling

const ROLE_NAME_MAX_LENGTH: usize = 80; // confirm exact constant in influxdb3_authz/src/role/role.rs
fn valid_role_name(name: &str) -> bool {
    !name.is_empty() && name.chars().count() <= ROLE_NAME_MAX_LENGTH
}

Type guard

fn check_role_name(name: &str) -> Result<&str, String> {
    if name.chars().count() <= ROLE_NAME_MAX_LENGTH { Ok(name) } else { Err(format!("role name exceeds {ROLE_NAME_MAX_LENGTH} chars")) }
}

Prevention

When it happens

Trigger: Calling the role-creation API (e.g. POST /api/v0/configure/... role endpoints or NewRoleName::new) with a name string whose character count exceeds ROLE_NAME_MAX_LENGTH.

Common situations: Auto-generated role names embedding long team/project names, concatenating prefixes like 'team-' plus an email or UUID, or names built from long org identifiers.

Understand the failure class

Background: "value must be between 0 and 1" / "out of range" / "must not be negative" errors: fixing range-validation failures across open-source libraries — this error's family across 42 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/27cf73372abde310. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/role/role.rs:90

        &self.0
    }

    pub fn into_inner(self) -> String {
        self.0
    }
}

impl std::fmt::Display for RoleName {
    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
        write!(f, "{}", self.0)
    }
}

#[derive(Debug, Clone, Error)]
pub enum NewRoleNameError {
    #[error("role name cannot be empty")]
    Empty,
    #[error("role name exceeds maximum length of {ROLE_NAME_MAX_LENGTH} characters")]
    TooLong,
    #[error("role name contains invalid characters: only alphanumeric and [{0}] are allowed")]
    InvalidCharacters(String),
}

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct RoleDescription(String);

impl RoleDescription {
    pub fn as_str(&self) -> &str {
        &self.0
    }

    pub fn new(description: &str) -> Result<Self, NewRoleDescriptionError> {
        if description.is_empty() {
            return Err(NewRoleDescriptionError::Empty);
        }

View on GitHub (pinned to 06200ef96b)