{"record":{"id":"0ca70372b73b256a","repo":"RocketChat/Rocket.Chat","slug":"error-id-param-not-provided","errorCode":"error-id-param-not-provided","errorMessage":"The parameter \"id\" is required","messagePattern":"The parameter \"id\" is required","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/settings.ts","lineNumber":410,"sourceCode":"\t'settings/:_id',\n\t{\n\t\tauthRequired: true,\n\t\tpermissionsRequired: {\n\t\t\tPOST: { permissions: ['edit-privileged-setting'], operation: 'hasAll' },\n\t\t},\n\t\ttwoFactorRequired: true,\n\t\tbody: settingsUpdateBodySchema,\n\t\tresponse: {\n\t\t\t200: settingByIdPostResponseSchema,\n\t\t\t400: validateBadRequestErrorResponse,\n\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t403: validateForbiddenErrorResponse,\n\t\t},\n\t},\n\tasync function action() {\n\t\tconst { _id } = this.urlParams;\n\t\tif (typeof _id !== 'string') {\n\t\t\tthrow new Meteor.Error('error-id-param-not-provided', 'The parameter \"id\" is required');\n\t\t}\n\n\t\tif (disableCustomScripts() && /^Custom_Script_/.test(_id)) {\n\t\t\treturn API.v1.forbidden('Custom scripts are disabled');\n\t\t}\n\n\t\tconst setting = await Settings.findOneNotHiddenById(_id);\n\n\t\tif (!setting) {\n\t\t\treturn API.v1.failure();\n\t\t}\n\n\t\tconst { bodyParams } = this;\n\n\t\tif (\n\t\t\tisSettingAction(setting) &&\n\t\t\tisSettingsUpdatePropsActions(bodyParams) &&\n\t\t\tbodyParams.execute &&","sourceCodeStart":392,"sourceCodeEnd":428,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/2a7de457074cbb4d4373fbd9a4e5bea292c9c764/apps/meteor/server/api/v1/settings.ts#L392-L428","documentation":"Thrown by POST /api/v1/settings/:_id when the URL path parameter _id is not a string (missing or empty). The route updates a single setting by its exact _id (e.g. \"Site_Name\" or \"Accounts_RegistrationForm\"). The check is a defensive runtime guard because normally the router would not match the route at all without a path segment.","triggerScenarios":"POST to /api/v1/settings/ (trailing slash, empty id), /api/v1/settings//, or a client that builds the URL with an undefined id variable producing an empty segment; also POST /api/v1/settings with no id, which never matches this route and 404s instead.","commonSituations":"Scripts that loop over a settings map and POST each key, where one key is undefined; templated URLs like `settings/${id}` with id null; double-slash bugs in reverse proxies or hand-built query strings.","solutions":["Always append a concrete setting _id: POST /api/v1/settings/Site_Name with body {\"value\": \"My Workspace\"}","Guard client-side: skip or fail early when the id variable is empty before building the URL","Confirm the _id exists via GET settings or GET settings/:_id first — a wrong (but present) id returns a normal failure, not this error","Check for proxy URL rewriting that strips the final path segment"],"exampleFix":"// before\nawait fetch(`${baseUrl}/api/v1/settings/${settingId}`, ...); // settingId undefined -> '/settings/'\n// after\nif (!settingId) throw new Error('settingId is required');\nawait fetch(`${baseUrl}/api/v1/settings/${encodeURIComponent(settingId)}`, ...);","handlingStrategy":"validation","validationCode":"if (typeof settingId !== 'string' || !settingId.trim()) throw new Error('setting _id is required in the URL path');\nawait fetch(`${base}/api/v1/settings/${encodeURIComponent(settingId)}`, opts);","typeGuard":"const isSettingId = (v: unknown): v is string => typeof v === 'string' && v.length > 0 && !v.includes('/');","tryCatchPattern":"catch (e) { if (e?.error === 'error-id-param-not-provided') rebuildUrlWithId(settingId); else throw e; }","preventionTips":["Never template URLs from unvalidated variables","Skip empty ids when iterating setting maps","Unit-test URL construction for undefined inputs"],"tags":["rest-api","validation","settings","url-params","admin"],"backgroundTag":"missing-required-argument","analyzedSha":"2a7de457074cbb4d4373fbd9a4e5bea292c9c764","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}