{"record":{"id":"08589e8ece7e1253","repo":"immich-app/immich","slug":"password-is-required","errorCode":null,"errorMessage":"password is required","messagePattern":"password is required","errorType":"validation","errorClass":"BadRequestException","httpStatus":400,"severity":"error","filePath":"server/src/services/user-admin.service.ts","lineNumber":37,"sourceCode":"import { getCalendarHeatmap } from 'src/services/shared/user-methods.js';\nimport { findOrFail } from 'src/utils/misc.js';\nimport { getPreferences, getPreferencesPartial, mergePreferences } from 'src/utils/preferences.js';\n\n@Injectable()\nexport class UserAdminService extends BaseService {\n  async search(auth: AuthDto, dto: UserAdminSearchDto): Promise<UserAdminResponseDto[]> {\n    const users = await this.userRepository.getList({\n      id: dto.id,\n      withDeleted: dto.withDeleted,\n    });\n    return users.map((user) => mapUserAdmin(user));\n  }\n\n  async create(dto: UserAdminCreateDto): Promise<UserAdminResponseDto> {\n    const { notify, ...userDto } = dto;\n    const config = await this.getConfig({ withCache: false });\n    if (!config.oauth.enabled && !userDto.password) {\n      throw new BadRequestException('password is required');\n    }\n\n    const user = await this.createUser(userDto);\n\n    await this.eventRepository.emit('UserSignup', {\n      notify: !!notify,\n      id: user.id,\n      password: userDto.password,\n    });\n\n    return mapUserAdmin(user);\n  }\n\n  async get(auth: AuthDto, id: string): Promise<UserAdminResponseDto> {\n    const user = await this.findOrFail(id, { withDeleted: true });\n    return mapUserAdmin(user);\n  }\n","sourceCodeStart":19,"sourceCodeEnd":55,"githubUrl":"https://github.com/immich-app/immich/blob/e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c/server/src/services/user-admin.service.ts#L19-L55","documentation":"Thrown by UserAdminService.create when a new user is being created without a password while OAuth is the only enabled auth method... actually the inverse: OAuth is DISABLED and no password was supplied, so the account could never log in. A local (password) user requires a password, hence the 400 BadRequest.","triggerScenarios":"POST /api/admin/users (UserAdminService.create) with a UserAdminCreateDto lacking password while server config has oauth.enabled=false. Also occurs when the password field is dropped by a client serializer or when switching the server from OAuth to password auth without backfilling passwords.","commonSituations":"Server admin created users while OAuth was enabled, then disabled OAuth; automation scripts creating users without a password field; notify=true flows that assume users will set their own password.","solutions":["Include a password in the create DTO when OAuth is disabled","Enable OAuth in the server settings if users should authenticate via OAuth instead","Have the user set a password via the password-reset flow after creation"],"exampleFix":"// before\nawait adminApi.createUser({ email: 'a@b.co', name: 'A' });\n// after\nawait adminApi.createUser({ email: 'a@b.co', name: 'A', password: generateInitialPassword() });","handlingStrategy":"validation","validationCode":"if (!oauthEnabled && !dto.password) {\n  throw new Error('password is required when OAuth is disabled');\n}","typeGuard":null,"tryCatchPattern":"try { await adminApi.createUser(dto); } catch (e) {\n  if (e.response?.status === 400 && /password is required/.test(e.response?.data?.message ?? '')) {\n    return adminApi.createUser({ ...dto, password: generateInitialPassword() });\n  }\n  throw e;\n}","preventionTips":["Check server OAuth settings before automating user creation","Always generate an initial password in admin scripts","Re-check config after switching auth methods (OAuth on/off)"],"tags":["validation","authentication","config"],"backgroundTag":"missing-required-argument","analyzedSha":"e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}