RocketChat/Rocket.Chat · error · Meteor.Error

error-invalid-user

error-invalid-user

Error message

Invalid User

What it means

addWebdavAccountByToken is an exported helper (not just a DDP method) that stores a WebDAV account using an OAuth token; it throws error-invalid-user when its first argument is empty. The DDP method wrapper checks login itself before delegating, so hitting this from the wrapper means the session dropped mid-call; hitting it directly means the caller imported the helper and passed a falsy userId.

Solutions

  1. Resolve and pass a real userId: in a DDP context use Meteor.userId(), in server code load the user first
  2. If calling via the DDP method addWebdavAccountByToken, re-login and retry when the session token is stale
  3. Do not invoke the helper with a placeholder or empty user — it performs no internal authentication

Example fix

// before
await addWebdavAccountByToken('', data); // → error-invalid-user

// after
const userId = Meteor.userId();
if (!userId) throw new Error('login required');
await addWebdavAccountByToken(userId, data);
Defensive patterns

Strategy: validation

Validate before calling

const userId = Meteor.userId();
if (!userId) throw new Error('login required');
await addWebdavAccountByToken(userId, data);

Try / catch

try {
  await addWebdavAccountByToken(userId, data);
} catch (e) {
  if (e.error === 'error-invalid-user') {
    // resolve a valid user before calling again; do not pass empty userId
  }
}

Prevention

When it happens

Trigger: Importing addWebdavAccountByToken and calling it with '', undefined, or null as userId; or a DDP call whose authentication expired between the method's own check and the helper call.

Common situations: OAuth callback handlers or server-side scripts that call the helper without resolving the current user first; refactoring code that assumed the helper does its own auth.

Understand the failure class

Background: error-invalid-user: "Invalid user" errors in Rocket.Chat — what they mean and how to fix them — this error's family across 2 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/3673b9010e6900b8. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts:21

import type { ServerMethods } from '@rocket.chat/ddp-client';
import { WebdavAccounts } from '@rocket.chat/models';
import { Match, check } from 'meteor/check';
import { Meteor } from 'meteor/meteor';

import { settings } from '../../../settings';
import { WebdavClientAdapter } from '../lib/webdavClientAdapter';

declare module '@rocket.chat/ddp-client' {
	// eslint-disable-next-line @typescript-eslint/naming-convention
	interface ServerMethods {
		addWebdavAccount(formData: IWebdavAccountPayload): boolean;
		addWebdavAccountByToken(data: IWebdavAccountPayload): boolean;
	}
}

export const addWebdavAccountByToken = async (userId: string, data: IWebdavAccountPayload): Promise<boolean> => {
	if (!userId) {
		throw new Meteor.Error('error-invalid-user', 'Invalid User', { method: 'addWebdavAccount' });
	}

	if (!settings.get('Webdav_Integration_Enabled')) {
		throw new Meteor.Error('error-not-allowed', 'WebDAV Integration Not Allowed', {
			method: 'addWebdavAccount',
		});
	}

	check(
		data,
		Match.ObjectIncluding({
			serverURL: String,
			token: Match.ObjectIncluding({
				access_token: String,
				token_type: String,
				refresh_token: Match.Optional(String),
			}),
			name: Match.Maybe(String),

View on GitHub (pinned to b2c16d5842)