influxdata/influxdb · critical
unimplemented
Error message
unimplemented
What it means
This is a Rust `unimplemented!()` panic raised inside `authorize_action` in influxdb3_authz when an access request targets a Token resource. Token-level CRUD authorization was never implemented in this authorizer; the code path is a deliberate placeholder. Hitting it means a request asked the authorizer to check permissions on a specific token, which the current implementation cannot do.
Solutions
- Do not route token-level authorization through this authorizer; implement an explicit AccessRequest::Token arm with real permission checks
- Handle/authorize token management at a higher layer (e.g. admin-only gate) before reaching authorize_action
- If you maintain the crate, replace unimplemented!() with a proper ResourceAuthorizationError variant
Example fix
// before
AccessRequest::Token(_token_id, _crud_actions) => unimplemented!(),
// after
AccessRequest::Token(token_id, crud_actions) =>
check_user_token_access(permissions, token_id, crud_actions), Defensive patterns
Strategy: type-guard
Type guard
fn is_token_request(req: &AccessRequest) -> bool {
matches!(req, AccessRequest::Token(_, _))
}
// skip/redirect authorization when is_token_request(&req) is true Prevention
- Never route token-management requests through authorize_action
- Guard new AccessRequest variants with explicit handling before merging
- Add tests covering every AccessRequest variant to catch panics early
When it happens
Trigger: An AccessRequest::Token(token_id, crud_actions) is dispatched during authorization, e.g. an API flow that manages/inspects tokens through the authorizer; also reproduced directly in tests like test_authorizer_authorization_failed and role_authoring_* tests.
Common situations: Developers wiring new token-management endpoints into the authz layer; enabling permission paths that enumerate per-token CRUD actions that were never supported.
Related errors
- authorization failure
- column id in series key should be valid
- duration not to overflow
- error reading time column
- Existing transaction for table should not exist
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/78fba57057e01d50.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/authorizer.rs:164
let required = role::role_permissions::RolePermission::new(action);
permissions.has_permission(&required)
}
},
AccessRequest::AdminToken(action) => {
let required = role::role_permissions::AdminTokenPermission::new(action);
permissions.has_permission(&required)
}
AccessRequest::ResourceToken(action) => {
let required = role::role_permissions::TokenPermission::new(action);
permissions.has_permission(&required)
}
AccessRequest::System(resource_id, actions) => {
check_user_system_access(permissions, resource_id, actions)
}
AccessRequest::AnyDatabase(actions) => {
check_user_database_access(permissions, None, actions)
}
AccessRequest::Token(_token_id, _crud_actions) => unimplemented!(),
};
if authorized {
Ok(())
} else {
Err(ResourceAuthorizationError::Unauthorized)
}
}
}
}
fn should_check_token(&self) -> bool {
true
}
fn upcast(&self) -> Arc<dyn IoxAuthorizer> {
let cloned_self = (*self).clone();
Arc::new(cloned_self) as _
}View on GitHub (pinned to 06200ef96b)