{"record":{"id":"3673b9010e6900b8","repo":"RocketChat/Rocket.Chat","slug":"error-invalid-user-3673b9","errorCode":"error-invalid-user","errorMessage":"Invalid User","messagePattern":"Invalid User","errorType":"exception","errorClass":"Meteor.Error","httpStatus":null,"severity":"error","filePath":"apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts","lineNumber":21,"sourceCode":"import type { ServerMethods } from '@rocket.chat/ddp-client';\nimport { WebdavAccounts } from '@rocket.chat/models';\nimport { Match, check } from 'meteor/check';\nimport { Meteor } from 'meteor/meteor';\n\nimport { settings } from '../../../settings';\nimport { WebdavClientAdapter } from '../lib/webdavClientAdapter';\n\ndeclare module '@rocket.chat/ddp-client' {\n\t// eslint-disable-next-line @typescript-eslint/naming-convention\n\tinterface ServerMethods {\n\t\taddWebdavAccount(formData: IWebdavAccountPayload): boolean;\n\t\taddWebdavAccountByToken(data: IWebdavAccountPayload): boolean;\n\t}\n}\n\nexport const addWebdavAccountByToken = async (userId: string, data: IWebdavAccountPayload): Promise<boolean> => {\n\tif (!userId) {\n\t\tthrow new Meteor.Error('error-invalid-user', 'Invalid User', { method: 'addWebdavAccount' });\n\t}\n\n\tif (!settings.get('Webdav_Integration_Enabled')) {\n\t\tthrow new Meteor.Error('error-not-allowed', 'WebDAV Integration Not Allowed', {\n\t\t\tmethod: 'addWebdavAccount',\n\t\t});\n\t}\n\n\tcheck(\n\t\tdata,\n\t\tMatch.ObjectIncluding({\n\t\t\tserverURL: String,\n\t\t\ttoken: Match.ObjectIncluding({\n\t\t\t\taccess_token: String,\n\t\t\t\ttoken_type: String,\n\t\t\t\trefresh_token: Match.Optional(String),\n\t\t\t}),\n\t\t\tname: Match.Maybe(String),","sourceCodeStart":3,"sourceCodeEnd":39,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts#L3-L39","documentation":"addWebdavAccountByToken is an exported helper (not just a DDP method) that stores a WebDAV account using an OAuth token; it throws error-invalid-user when its first argument is empty. The DDP method wrapper checks login itself before delegating, so hitting this from the wrapper means the session dropped mid-call; hitting it directly means the caller imported the helper and passed a falsy userId.","triggerScenarios":"Importing addWebdavAccountByToken and calling it with '', undefined, or null as userId; or a DDP call whose authentication expired between the method's own check and the helper call.","commonSituations":"OAuth callback handlers or server-side scripts that call the helper without resolving the current user first; refactoring code that assumed the helper does its own auth.","solutions":["Resolve and pass a real userId: in a DDP context use Meteor.userId(), in server code load the user first","If calling via the DDP method addWebdavAccountByToken, re-login and retry when the session token is stale","Do not invoke the helper with a placeholder or empty user — it performs no internal authentication"],"exampleFix":"// before\nawait addWebdavAccountByToken('', data); // → error-invalid-user\n\n// after\nconst userId = Meteor.userId();\nif (!userId) throw new Error('login required');\nawait addWebdavAccountByToken(userId, data);","handlingStrategy":"validation","validationCode":"const userId = Meteor.userId();\nif (!userId) throw new Error('login required');\nawait addWebdavAccountByToken(userId, data);","typeGuard":null,"tryCatchPattern":"try {\n  await addWebdavAccountByToken(userId, data);\n} catch (e) {\n  if (e.error === 'error-invalid-user') {\n    // resolve a valid user before calling again; do not pass empty userId\n  }\n}","preventionTips":["Never call exported server helpers with a placeholder userId","Resolve the current user at call time, not from stale cached state","Prefer the DDP method wrapper, which performs its own auth check"],"tags":["meteor","webdav","authentication","oauth"],"backgroundTag":"meteor-error-invalid-user","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}