RocketChat/Rocket.Chat · error · Meteor.Error
error-invalid-user
error-invalid-user
Error message
Invalid User
What it means
addWebdavAccountByToken is an exported helper (not just a DDP method) that stores a WebDAV account using an OAuth token; it throws error-invalid-user when its first argument is empty. The DDP method wrapper checks login itself before delegating, so hitting this from the wrapper means the session dropped mid-call; hitting it directly means the caller imported the helper and passed a falsy userId.
Solutions
- Resolve and pass a real userId: in a DDP context use Meteor.userId(), in server code load the user first
- If calling via the DDP method addWebdavAccountByToken, re-login and retry when the session token is stale
- Do not invoke the helper with a placeholder or empty user — it performs no internal authentication
Example fix
// before
await addWebdavAccountByToken('', data); // → error-invalid-user
// after
const userId = Meteor.userId();
if (!userId) throw new Error('login required');
await addWebdavAccountByToken(userId, data); Defensive patterns
Strategy: validation
Validate before calling
const userId = Meteor.userId();
if (!userId) throw new Error('login required');
await addWebdavAccountByToken(userId, data); Try / catch
try {
await addWebdavAccountByToken(userId, data);
} catch (e) {
if (e.error === 'error-invalid-user') {
// resolve a valid user before calling again; do not pass empty userId
}
} Prevention
- Never call exported server helpers with a placeholder userId
- Resolve the current user at call time, not from stale cached state
- Prefer the DDP method wrapper, which performs its own auth check
When it happens
Trigger: Importing addWebdavAccountByToken and calling it with '', undefined, or null as userId; or a DDP call whose authentication expired between the method's own check and the helper call.
Common situations: OAuth callback handlers or server-side scripts that call the helper without resolving the current user first; refactoring code that assumed the helper does its own auth.
Understand the failure class
Background: error-invalid-user: "Invalid user" errors in Rocket.Chat — what they mean and how to fix them — this error's family across 2 libraries.
Related errors
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/3673b9010e6900b8.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts:21
import type { ServerMethods } from '@rocket.chat/ddp-client';
import { WebdavAccounts } from '@rocket.chat/models';
import { Match, check } from 'meteor/check';
import { Meteor } from 'meteor/meteor';
import { settings } from '../../../settings';
import { WebdavClientAdapter } from '../lib/webdavClientAdapter';
declare module '@rocket.chat/ddp-client' {
// eslint-disable-next-line @typescript-eslint/naming-convention
interface ServerMethods {
addWebdavAccount(formData: IWebdavAccountPayload): boolean;
addWebdavAccountByToken(data: IWebdavAccountPayload): boolean;
}
}
export const addWebdavAccountByToken = async (userId: string, data: IWebdavAccountPayload): Promise<boolean> => {
if (!userId) {
throw new Meteor.Error('error-invalid-user', 'Invalid User', { method: 'addWebdavAccount' });
}
if (!settings.get('Webdav_Integration_Enabled')) {
throw new Meteor.Error('error-not-allowed', 'WebDAV Integration Not Allowed', {
method: 'addWebdavAccount',
});
}
check(
data,
Match.ObjectIncluding({
serverURL: String,
token: Match.ObjectIncluding({
access_token: String,
token_type: String,
refresh_token: Match.Optional(String),
}),
name: Match.Maybe(String),View on GitHub (pinned to b2c16d5842)