{"record":{"id":"3fc147e9e6135186","repo":"Mintplex-Labs/anything-llm","slug":"no-docpath-provided-in-request","errorCode":null,"errorMessage":"No docPath provided in request","messagePattern":"No docPath provided in request","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"server/utils/files/index.js","lineNumber":31,"sourceCode":"    ? path.resolve(__dirname, `../../storage/direct-uploads`)\n    : path.resolve(process.env.STORAGE_DIR, `direct-uploads`);\nconst vectorCachePath =\n  process.env.NODE_ENV === \"development\"\n    ? path.resolve(__dirname, `../../storage/vector-cache`)\n    : path.resolve(process.env.STORAGE_DIR, `vector-cache`);\nconst hotdirPath =\n  process.env.NODE_ENV === \"development\"\n    ? path.resolve(__dirname, `../../../collector/hotdir`)\n    : path.resolve(process.env.STORAGE_DIR, `../../collector/hotdir`);\nconst generatedImagesPath =\n  process.env.NODE_ENV === \"development\"\n    ? path.resolve(__dirname, `../../storage/generated-images`)\n    : path.resolve(process.env.STORAGE_DIR, `generated-images`);\n\n// Should take in a folder that is a subfolder of documents\n// eg: youtube-subject/video-123.json\nasync function fileData(filePath = null) {\n  if (!filePath) throw new Error(\"No docPath provided in request\");\n  // The raw filePath is what gets persisted as a document's `docpath` and later\n  // resolved directly by background jobs, so it must stay inside the documents\n  // folder on its own and not only after normalization strips a leading `../`.\n  if (!isWithin(documentsPath, path.resolve(documentsPath, filePath)))\n    return null;\n  const fullFilePath = path.resolve(documentsPath, normalizePath(filePath));\n  if (!fs.existsSync(fullFilePath) || !isWithin(documentsPath, fullFilePath))\n    return null;\n\n  const data = fs.readFileSync(fullFilePath, \"utf8\");\n  return JSON.parse(data);\n}\n\nfunction listFolders() {\n  if (!fs.existsSync(documentsPath)) fs.mkdirSync(documentsPath);\n  const folders = [];\n\n  for (const file of fs.readdirSync(documentsPath)) {","sourceCodeStart":13,"sourceCodeEnd":49,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/f92433b4ea0598492a1e6645ea22addbb4dd1287/server/utils/files/index.js#L13-L49","documentation":"fileData resolves a document's docpath to a file under the storage documents folder and throws immediately when called with a null/undefined/empty path. It is a guard against callers invoking the document lookup without the required docPath, e.g. a malformed request to a document endpoint.","triggerScenarios":"Calling fileData(null), fileData(), or an API route that forwards an empty docPath/doc query parameter into fileData.","commonSituations":"Frontend sending a request without the docPath query param; URL-encoded docPath lost in a redirect; API client calling the document endpoint with a missing field; older clients after the API contract changed to require docPath.","solutions":["Ensure the caller (frontend or API client) always sends the docPath parameter.","Check the endpoint's query/body for the docPath field before invoking fileData.","Return a 400 to clients early instead of letting the guard throw.","Encode the docPath correctly in the request URL (encodeURIComponent) so it is not dropped."],"exampleFix":"// before\nawait fileData(searchParams.docPath);\n// after\nconst docPath = searchParams.get('docPath');\nif (!docPath) return response.status(400).json({ error: 'docPath is required' });\nawait fileData(docPath);","handlingStrategy":"validation","validationCode":"// caller-side check before hitting the endpoint\nconst docPath = new URL(request.url).searchParams.get('docPath');\nif (!docPath) return response.status(400).json({ error: 'docPath query parameter is required' });","typeGuard":"function hasDocPath(args) {\n  return typeof args?.docPath === 'string' && args.docPath.trim().length > 0;\n}","tryCatchPattern":"try {\n  const data = await fileData(docPath);\n} catch (e) {\n  if (/No docPath provided/.test(e.message)) {\n    return response.status(400).json({ error: 'docPath is required' });\n  }\n  throw e;\n}","preventionTips":["Always pass the docPath query/body field from the frontend.","encodeURIComponent the docPath so it survives URL parsing.","Add early 400 validation in the endpoint handler before calling fileData.","Write an integration test hitting the endpoint without docPath to assert 400."],"tags":["missing-argument","files","validation","api"],"backgroundTag":"missing-required-argument","analyzedSha":"f92433b4ea0598492a1e6645ea22addbb4dd1287","analyzedAt":"2026-09-22T02:13:38.154Z","contentChangedAt":"2026-09-22T02:13:38.154Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}