gRPC

gRPC 7 PERMISSION_DENIED vs 16 UNAUTHENTICATED

Both gRPC 7 (PERMISSION_DENIED) and 16 (UNAUTHENTICATED) belong to the gRPC Status Codes category. 7 indicates that the caller does not have permission to execute the specified operation. This is not for unauthenticated callers — use UNAUTHENTICATED instead. Meanwhile, 16 means that the request does not have valid authentication credentials for the operation.

คำอธิบาย

The caller does not have permission to execute the specified operation. This is not for unauthenticated callers — use UNAUTHENTICATED instead.

เมื่อคุณพบเห็น

The authenticated user lacks the required role, scope, or policy to perform this action. Different from UNAUTHENTICATED (code 16), which means no credentials at all.

วิธีแก้ไข

Verify the caller has the correct IAM role, API scope, or access policy. Check RBAC configuration on the server side.

คำอธิบาย

The request does not have valid authentication credentials for the operation.

เมื่อคุณพบเห็น

No credentials were provided, or the provided token/certificate is expired or invalid. Different from PERMISSION_DENIED (code 7), which means authenticated but not authorized.

วิธีแก้ไข

Provide valid authentication credentials (e.g., refresh the OAuth token, regenerate the API key, or renew the client certificate).

ความแตกต่างหลัก

1.

gRPC 7: The caller does not have permission to execute the specified operation. This is not for unauthenticated callers — use UNAUTHENTICATED instead.

2.

gRPC 16: The request does not have valid authentication credentials for the operation.

3.

You encounter 7 when the authenticated user lacks the required role, scope, or policy to perform this action. Different from UNAUTHENTICATED (code 16), which means no credentials at all.

4.

You encounter 16 when no credentials were provided, or the provided token/certificate is expired or invalid. Different from PERMISSION_DENIED (code 7), which means authenticated but not authorized.

ควรใช้อันไหนเมื่อไร

For 7 (PERMISSION_DENIED): Verify the caller has the correct IAM role, API scope, or access policy. Check RBAC configuration on the server side. For 16 (UNAUTHENTICATED): Provide valid authentication credentials (e.g., refresh the OAuth token, regenerate the API key, or renew the client certificate).

เรียนรู้เพิ่มเติม