RocketChat/Rocket.Chat · error · Error

error-invalid-param

Error message

error-invalid-param

What it means

Thrown by GET email-inbox/:_id when the _id URL segment is missing/empty: the action destructures this.urlParams._id and throws new Error('error-invalid-param') when falsy before querying EmailInbox.findOneById. Because the route is defined with an :_id path parameter, this normally only fires when the path matched with an empty segment (e.g. trailing slash) — otherwise a missing id yields 404 routing.

Solutions

  1. Always include the id: GET /api/v1/email-inbox/<_id>.
  2. Guard client-side: skip the request when the id is empty instead of sending '/email-inbox/'.
  3. Use email-inbox.list to discover valid _id values when unsure.

Example fix

// before
fetch(`/api/v1/email-inbox/${id}`); // id may be ''

// after
if (id) fetch(`/api/v1/email-inbox/${id}`);
Defensive patterns

Strategy: validation

Validate before calling

function inboxUrl(id: string | undefined) {
  if (!id) throw new Error('email-inbox _id is required');
  return `/api/v1/email-inbox/${encodeURIComponent(id)}`;
}

Type guard

const isNonEmptyId = (v: unknown): v is string => typeof v === 'string' && v.length > 0;

Prevention

When it happens

Trigger: Calling GET /api/v1/email-inbox/ (trailing slash, empty segment) or a URL where the _id segment is stripped by client-side path building.

Common situations: Template strings that leave the id empty when state is not yet loaded ('/api/v1/email-inbox/' + id with id=''); proxies that normalize away an empty segment; exploratory curl with the path truncated.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/1c470736364f1bea. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/email-inbox.ts:146

								properties: {
									success: { type: 'boolean', enum: [true] },
								},
								required: ['success'],
							},
						],
					},
					{ type: 'null' },
				],
			}),
			401: validateUnauthorizedErrorResponse,
			403: validateForbiddenErrorResponse,
			404: validateNotFoundErrorResponse,
		},
	},
	async function action() {
		const { _id } = this.urlParams;
		if (!_id) {
			throw new Error('error-invalid-param');
		}
		const emailInbox = await EmailInbox.findOneById(_id);

		if (!emailInbox) {
			return API.v1.notFound();
		}

		return API.v1.success(emailInbox);
	},
);

API.v1.delete(
	'email-inbox/:_id',
	{
		authRequired: true,
		permissionsRequired: ['manage-email-inbox'],
		response: {
			200: ajv.compile<{ _id: string }>({

View on GitHub (pinned to b2c16d5842)