RocketChat/Rocket.Chat · error · Error

auth option should be of the form "username:password"

Error message

auth option should be of the form "username:password"

What it means

FileSystem:UserDataFiles.get serves GDPR data-export downloads from the FileSystem store; when anything in the try throws (typically fsp.stat ENOENT — the export record exists but the exported file is gone from disk), it returns a bodyless 404. Like the avatars store, a stat that resolves non-file silently sends nothing.

Solutions

  1. Confirm the export still exists at the computed path and that FileUpload_FileSystemPath has not changed
  2. Regenerate the export for the user (the old link will not heal itself)
  3. Add logging to the catch to distinguish ENOENT from permission failures

Example fix

// before
} catch (e) {
	res.writeHead(404);
	res.end();
}
// after
} catch (e) {
	SystemLogger.error({ msg: 'user-data file serve failed', fileId: file._id, code: e.code });
	res.writeHead(404);
	res.end();
}
Defensive patterns

Strategy: validation

Validate before calling

const p = await store.getFilePath(file._id, file);
const exists = await fsp.stat(p).then((s) => s.isFile()).catch(() => false);
if (!exists) { /* tell the user to regenerate the export; do not link a dead file */ }

Try / catch

Catch and log e.code for user-data file serving failures; ENOENT should mark the export record as expired/missing so the UI can offer regeneration rather than a naked 404.

Prevention

When it happens

Trigger: UserDataFiles document exists but the export file is missing: FileUpload_FileSystemPath changed since the export was generated; the export file was purged by cleanup jobs or the volume was recreated; DB restored without the exports directory.

Common situations: Expired export files after retention cleanup; storage migrations; volume mounting issues in containerized deployments; users clicking old export links from earlier emails.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/058d1527fed41f5a. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/app/apps/server/bridges/http.ts:38

	}

	protected async call(info: IHttpBridgeRequestInfo): Promise<IHttpResponse> {
		// begin comptability with old HTTP.call API
		const url = new URL(info.url);

		const { request, method } = info;

		const { headers = {} } = request;

		let { content } = request;

		if (!content && typeof request.data === 'object') {
			content = request.data;
		}

		if (request.auth) {
			if (request.auth.indexOf(':') < 0) {
				throw new Error('auth option should be of the form "username:password"');
			}

			const base64 = Buffer.from(request.auth, 'ascii').toString('base64');
			headers.Authorization = `Basic ${base64}`;
		}

		let paramsForBody;

		if (content || isGetOrHead(method)) {
			if (request.params) {
				Object.keys(request.params).forEach((key) => {
					if (request.params?.[key]) {
						url.searchParams.append(key, request.params?.[key]);
					}
				});
			}
		} else {
			paramsForBody = request.params;

View on GitHub (pinned to b2c16d5842)