RocketChat/Rocket.Chat · error · Error

invalid-calendar-event

Error message

invalid-calendar-event

What it means

Thrown by POST calendar-events.update when Calendar.get(eventId) returns no event, or the event's uid does not match the authenticated user. The check doubles as existence and ownership validation: only the creator of a calendar event may modify it, and a missing event is deliberately reported the same way to avoid leaking event existence.

Solutions

  1. Re-fetch the user's events (GET calendar-events.list or equivalent) and update from a fresh ID
  2. Handle 4xx as terminal: remove or refresh the stale event in the UI instead of retrying the same eventId
  3. Confirm the authenticated user is the event creator before offering an edit action
Defensive patterns

Strategy: validation

Validate before calling

const events = await GET('/api/v1/calendar-events.list'); // or equivalent fetch
const owned = events.find((ev) => ev._id === eventId && ev.uid === currentUserId);
if (!owned) throw new Error('Event missing or not editable by this user');

Try / catch

try { await POST('/api/v1/calendar-events.update', body); } catch (e) {
  if (e.error === 'invalid-calendar-event') { /* drop stale event, refresh list */ }
}

Prevention

When it happens

Trigger: POST /api/v1/calendar-events.update with an eventId that does not exist, that was already deleted, or that belongs to a different user (events are per-user, not per-room).

Common situations: Event was deleted in another tab/session and the client still shows it; stale eventId persisted in local state after re-login as a different user; ID typo or truncated copy-paste; two clients racing where one deletes while the other edits.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/15cbfa4675b9625c. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/calendar.ts:182

API.v1.post(
	'calendar-events.update',
	{
		authRequired: true,
		body: isCalendarEventUpdateProps,
		response: {
			200: successSchema,
			400: validateBadRequestErrorResponse,
			401: validateUnauthorizedErrorResponse,
		},
	},
	async function action() {
		const { userId } = this;
		const { eventId, startTime, endTime, subject, description, meetingUrl, reminderMinutesBeforeStart, busy } = this.bodyParams;

		const event = await Calendar.get(eventId);

		if (event?.uid !== userId) {
			throw new Error('invalid-calendar-event');
		}

		await Calendar.update(eventId, {
			startTime: new Date(startTime),
			...(endTime && { endTime: new Date(endTime) }),
			subject,
			description,
			meetingUrl,
			reminderMinutesBeforeStart,
			...(typeof busy === 'boolean' && { busy }),
		});

		return API.v1.success();
	},
);

API.v1.post(
	'calendar-events.delete',

View on GitHub (pinned to b2c16d5842)