RocketChat/Rocket.Chat · error · Meteor.Error

error-id-param-not-provided

error-id-param-not-provided

Error message

The parameter "id" is required

What it means

Thrown by POST /api/v1/settings/:_id when the URL path parameter _id is not a string (missing or empty). The route updates a single setting by its exact _id (e.g. "Site_Name" or "Accounts_RegistrationForm"). The check is a defensive runtime guard because normally the router would not match the route at all without a path segment.

Solutions

  1. Always append a concrete setting _id: POST /api/v1/settings/Site_Name with body {"value": "My Workspace"}
  2. Guard client-side: skip or fail early when the id variable is empty before building the URL
  3. Confirm the _id exists via GET settings or GET settings/:_id first — a wrong (but present) id returns a normal failure, not this error
  4. Check for proxy URL rewriting that strips the final path segment

Example fix

// before
await fetch(`${baseUrl}/api/v1/settings/${settingId}`, ...); // settingId undefined -> '/settings/'
// after
if (!settingId) throw new Error('settingId is required');
await fetch(`${baseUrl}/api/v1/settings/${encodeURIComponent(settingId)}`, ...);
Defensive patterns

Strategy: validation

Validate before calling

if (typeof settingId !== 'string' || !settingId.trim()) throw new Error('setting _id is required in the URL path');
await fetch(`${base}/api/v1/settings/${encodeURIComponent(settingId)}`, opts);

Type guard

const isSettingId = (v: unknown): v is string => typeof v === 'string' && v.length > 0 && !v.includes('/');

Try / catch

catch (e) { if (e?.error === 'error-id-param-not-provided') rebuildUrlWithId(settingId); else throw e; }

Prevention

When it happens

Trigger: POST to /api/v1/settings/ (trailing slash, empty id), /api/v1/settings//, or a client that builds the URL with an undefined id variable producing an empty segment; also POST /api/v1/settings with no id, which never matches this route and 404s instead.

Common situations: Scripts that loop over a settings map and POST each key, where one key is undefined; templated URLs like `settings/${id}` with id null; double-slash bugs in reverse proxies or hand-built query strings.

Understand the failure class

Background: "missing required argument" and "the following required arguments were not provided": what required-argument errors mean and how to fix them — this error's family across 20 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@2a7de45707 (2026-08-18). Data as JSON: /api/errors/0ca70372b73b256a. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/settings.ts:410

	'settings/:_id',
	{
		authRequired: true,
		permissionsRequired: {
			POST: { permissions: ['edit-privileged-setting'], operation: 'hasAll' },
		},
		twoFactorRequired: true,
		body: settingsUpdateBodySchema,
		response: {
			200: settingByIdPostResponseSchema,
			400: validateBadRequestErrorResponse,
			401: validateUnauthorizedErrorResponse,
			403: validateForbiddenErrorResponse,
		},
	},
	async function action() {
		const { _id } = this.urlParams;
		if (typeof _id !== 'string') {
			throw new Meteor.Error('error-id-param-not-provided', 'The parameter "id" is required');
		}

		if (disableCustomScripts() && /^Custom_Script_/.test(_id)) {
			return API.v1.forbidden('Custom scripts are disabled');
		}

		const setting = await Settings.findOneNotHiddenById(_id);

		if (!setting) {
			return API.v1.failure();
		}

		const { bodyParams } = this;

		if (
			isSettingAction(setting) &&
			isSettingsUpdatePropsActions(bodyParams) &&
			bodyParams.execute &&

View on GitHub (pinned to 2a7de45707)