RocketChat/Rocket.Chat · warning · Error

Invalid Slash Command parameter provided, it must be a…

Error message

Invalid Slash Command parameter provided, it must be a valid ISlashCommand object.

What it means

The /custom-sounds/<file> connect handler distinguishes malformed requests from unknown sounds: if the path segment after the prefix is empty (fileId falsy after stripping the query string), it responds 403 'Forbidden'. This is a URL-shape guard, not an authorization check — no sound id was supplied at all.

Solutions

  1. Always build the URL as /custom-sounds/<soundFileId>(.<ext>) with a non-empty id
  2. Fix the client-side variable that resolved to empty/undefined before rendering the URL
  3. Guard proxies/rewrites so the file segment survives

Example fix

// before
const url = `/custom-sounds/${sound && sound.file ? sound.file._id : ''}`;
// after
const url = sound?.file?._id ? `/custom-sounds/${sound.file._id}.mp3` : '/sounds/chime.mp3';
Defensive patterns

Strategy: validation

Validate before calling

const soundUrl = (id?: string, ext = 'mp3') => (id ? `/custom-sounds/${encodeURIComponent(id)}.${ext}` : null);

Type guard

const isValidSoundPath = (fileId?: string): boolean => Boolean(fileId && fileId.trim().length > 0);

Prevention

When it happens

Trigger: GET /custom-sounds/ or /custom-sounds/?v=2 where the URL yields an empty file id; reverse proxies or rewrites that strip the segment; client code building the URL from an undefined/null variable producing an empty string.

Common situations: Bots and probes hitting the bare prefix; template bugs emitting empty src attributes for notification sounds; refactors that renamed the sound field to undefined.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/e5d98ef08b715992. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/app/apps/server/bridges/commands.ts:139

	}

	protected async unregisterCommand(command: string, appId: string): Promise<void> {
		this.orch.debugLog(`The App ${appId} is unregistering the command: "${command}"`);

		if (typeof command !== 'string' || command.trim().length === 0) {
			throw new Error('Invalid command parameter provided, must be a string.');
		}

		const cmd = command.toLowerCase();
		this.disabledCommands.delete(cmd);
		delete slashCommands.commands[cmd];

		void this.orch.getNotifier().commandRemoved(cmd);
	}

	private _verifyCommand(command: ISlashCommand): void {
		if (typeof command !== 'object') {
			throw new Error('Invalid Slash Command parameter provided, it must be a valid ISlashCommand object.');
		}

		if (typeof command.command !== 'string') {
			throw new Error('Invalid Slash Command parameter provided, it must be a valid ISlashCommand object.');
		}

		if (command.i18nParamsExample && typeof command.i18nParamsExample !== 'string') {
			throw new Error('Invalid Slash Command parameter provided, it must be a valid ISlashCommand object.');
		}

		if (command.i18nDescription && typeof command.i18nDescription !== 'string') {
			throw new Error('Invalid Slash Command parameter provided, it must be a valid ISlashCommand object.');
		}

		if (typeof command.providesPreview !== 'boolean') {
			throw new Error('Invalid Slash Command parameter provided, it must be a valid ISlashCommand object.');
		}
	}

View on GitHub (pinned to b2c16d5842)