influxdata/influxdb · critical

unimplemented

Error message

unimplemented

What it means

This is a Rust `unimplemented!()` panic raised inside `authorize_action` in influxdb3_authz when an access request targets a Token resource. Token-level CRUD authorization was never implemented in this authorizer; the code path is a deliberate placeholder. Hitting it means a request asked the authorizer to check permissions on a specific token, which the current implementation cannot do.

Solutions

  1. Do not route token-level authorization through this authorizer; implement an explicit AccessRequest::Token arm with real permission checks
  2. Handle/authorize token management at a higher layer (e.g. admin-only gate) before reaching authorize_action
  3. If you maintain the crate, replace unimplemented!() with a proper ResourceAuthorizationError variant

Example fix

// before
AccessRequest::Token(_token_id, _crud_actions) => unimplemented!(),
// after
AccessRequest::Token(token_id, crud_actions) =>
    check_user_token_access(permissions, token_id, crud_actions),
Defensive patterns

Strategy: type-guard

Type guard

fn is_token_request(req: &AccessRequest) -> bool {
    matches!(req, AccessRequest::Token(_, _))
}
// skip/redirect authorization when is_token_request(&req) is true

Prevention

When it happens

Trigger: An AccessRequest::Token(token_id, crud_actions) is dispatched during authorization, e.g. an API flow that manages/inspects tokens through the authorizer; also reproduced directly in tests like test_authorizer_authorization_failed and role_authoring_* tests.

Common situations: Developers wiring new token-management endpoints into the authz layer; enabling permission paths that enumerate per-token CRUD actions that were never supported.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/78fba57057e01d50. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/authorizer.rs:164

                            let required = role::role_permissions::RolePermission::new(action);
                            permissions.has_permission(&required)
                        }
                    },
                    AccessRequest::AdminToken(action) => {
                        let required = role::role_permissions::AdminTokenPermission::new(action);
                        permissions.has_permission(&required)
                    }
                    AccessRequest::ResourceToken(action) => {
                        let required = role::role_permissions::TokenPermission::new(action);
                        permissions.has_permission(&required)
                    }
                    AccessRequest::System(resource_id, actions) => {
                        check_user_system_access(permissions, resource_id, actions)
                    }
                    AccessRequest::AnyDatabase(actions) => {
                        check_user_database_access(permissions, None, actions)
                    }
                    AccessRequest::Token(_token_id, _crud_actions) => unimplemented!(),
                };
                if authorized {
                    Ok(())
                } else {
                    Err(ResourceAuthorizationError::Unauthorized)
                }
            }
        }
    }

    fn should_check_token(&self) -> bool {
        true
    }

    fn upcast(&self) -> Arc<dyn IoxAuthorizer> {
        let cloned_self = (*self).clone();
        Arc::new(cloned_self) as _
    }

View on GitHub (pinned to 06200ef96b)