{"record":{"id":"15cbfa4675b9625c","repo":"RocketChat/Rocket.Chat","slug":"invalid-calendar-event","errorCode":null,"errorMessage":"invalid-calendar-event","messagePattern":"invalid-calendar-event","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"apps/meteor/server/api/v1/calendar.ts","lineNumber":182,"sourceCode":"API.v1.post(\n\t'calendar-events.update',\n\t{\n\t\tauthRequired: true,\n\t\tbody: isCalendarEventUpdateProps,\n\t\tresponse: {\n\t\t\t200: successSchema,\n\t\t\t400: validateBadRequestErrorResponse,\n\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t},\n\t},\n\tasync function action() {\n\t\tconst { userId } = this;\n\t\tconst { eventId, startTime, endTime, subject, description, meetingUrl, reminderMinutesBeforeStart, busy } = this.bodyParams;\n\n\t\tconst event = await Calendar.get(eventId);\n\n\t\tif (event?.uid !== userId) {\n\t\t\tthrow new Error('invalid-calendar-event');\n\t\t}\n\n\t\tawait Calendar.update(eventId, {\n\t\t\tstartTime: new Date(startTime),\n\t\t\t...(endTime && { endTime: new Date(endTime) }),\n\t\t\tsubject,\n\t\t\tdescription,\n\t\t\tmeetingUrl,\n\t\t\treminderMinutesBeforeStart,\n\t\t\t...(typeof busy === 'boolean' && { busy }),\n\t\t});\n\n\t\treturn API.v1.success();\n\t},\n);\n\nAPI.v1.post(\n\t'calendar-events.delete',","sourceCodeStart":164,"sourceCodeEnd":200,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/calendar.ts#L164-L200","documentation":"Thrown by POST calendar-events.update when Calendar.get(eventId) returns no event, or the event's uid does not match the authenticated user. The check doubles as existence and ownership validation: only the creator of a calendar event may modify it, and a missing event is deliberately reported the same way to avoid leaking event existence.","triggerScenarios":"POST /api/v1/calendar-events.update with an eventId that does not exist, that was already deleted, or that belongs to a different user (events are per-user, not per-room).","commonSituations":"Event was deleted in another tab/session and the client still shows it; stale eventId persisted in local state after re-login as a different user; ID typo or truncated copy-paste; two clients racing where one deletes while the other edits.","solutions":["Re-fetch the user's events (GET calendar-events.list or equivalent) and update from a fresh ID","Handle 4xx as terminal: remove or refresh the stale event in the UI instead of retrying the same eventId","Confirm the authenticated user is the event creator before offering an edit action"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"const events = await GET('/api/v1/calendar-events.list'); // or equivalent fetch\nconst owned = events.find((ev) => ev._id === eventId && ev.uid === currentUserId);\nif (!owned) throw new Error('Event missing or not editable by this user');","typeGuard":null,"tryCatchPattern":"try { await POST('/api/v1/calendar-events.update', body); } catch (e) {\n  if (e.error === 'invalid-calendar-event') { /* drop stale event, refresh list */ }\n}","preventionTips":["Edit only events returned by a fresh list fetch for the same user","Clear persisted event IDs on logout to avoid cross-user staleness"],"tags":["calendar","rest-api","ownership","not-found","rocket-chat"],"backgroundTag":"resource-not-owned","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}