{"record":{"id":"54711f9b7a238092","repo":"RocketChat/Rocket.Chat","slug":"error-param-not-provided","errorCode":"error-param-not-provided","errorMessage":"Query param \"role\" is required","messagePattern":"Query param \"role\" is required","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/roles.ts","lineNumber":190,"sourceCode":"\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t\t403: validateForbiddenErrorResponse,\n\t\t\t},\n\t\t},\n\t\tasync function action() {\n\t\t\tconst { roomId, role } = this.queryParams;\n\t\t\tconst { offset, count = 50 } = await getPaginationItems(this.queryParams);\n\n\t\t\tconst projection = {\n\t\t\t\tname: 1,\n\t\t\t\tusername: 1,\n\t\t\t\temails: 1,\n\t\t\t\tavatarETag: 1,\n\t\t\t\tcreatedAt: 1,\n\t\t\t\t_updatedAt: 1,\n\t\t\t};\n\n\t\t\tif (!role) {\n\t\t\t\tthrow new Meteor.Error('error-param-not-provided', 'Query param \"role\" is required');\n\t\t\t}\n\t\t\tif (roomId && !(await hasPermissionAsync(this.user, 'view-other-user-channels'))) {\n\t\t\t\tthrow new Meteor.Error('error-not-allowed', 'Not allowed');\n\t\t\t}\n\n\t\t\tconst options = { projection: { _id: 1 } };\n\t\t\tconst roleData = await Roles.findOneById<Pick<IRole, '_id'>>(role, options);\n\n\t\t\tif (!roleData) {\n\t\t\t\tthrow new Meteor.Error('error-invalid-roleId');\n\t\t\t}\n\n\t\t\tconst { cursor, totalCount } = await getUsersInRolePaginated(roleData._id, roomId, {\n\t\t\t\tlimit: count,\n\t\t\t\tsort: { username: 1 },\n\t\t\t\tskip: offset,\n\t\t\t\tprojection,\n\t\t\t});","sourceCodeStart":172,"sourceCodeEnd":208,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/roles.ts#L172-L208","documentation":"Thrown by GET /api/v1/roles.getUsersInRole (requires access-permissions) when the `role` query param is missing. The route's AJV query schema deliberately leaves `role` optional, so schema validation passes and the handler itself enforces the requirement — calling the endpoint bare, or with only pagination params, produces this error-param-not-provided.","triggerScenarios":"GET /api/v1/roles.getUsersInRole with no role param; passing the role in the body of a GET; typo'ing the param name (roles=, roleId=) so `role` stays undefined; building query strings conditionally and skipping the role clause.","commonSituations":"Optional-chaining bugs in client code (params.role ?? undefined sent as nothing); copied curl commands with the role value accidentally deleted; API wrappers that drop falsy params silently.","solutions":["Always include role — GET /api/v1/roles.getUsersInRole?role=<role _id>","Remember this endpoint wants the role's _id, not its display name (see error-invalid-roleId)","Add a client-side assert that the role param is a non-empty string before firing the request"],"exampleFix":"// before\nconst qs = new URLSearchParams({ offset: '0', ...(roomId && { roomId }) }); // role forgotten\n\n// after\nif (!role) throw new Error('role is required');\nconst qs = new URLSearchParams({ role, offset: '0', ...(roomId && { roomId }) });","handlingStrategy":"validation","validationCode":"if (typeof role !== 'string' || role.length === 0) {\n  throw new Error('roles.getUsersInRole requires a non-empty role query param');\n}\nawait sdk.get('roles.getUsersInRole', { role, ...(roomId && { roomId }) });","typeGuard":"const hasRoleQueryParam = (q: Record<string, unknown>): q is { role: string } =>\n  typeof q.role === 'string' && q.role.length > 0;","tryCatchPattern":"catch 'error-param-not-provided' and fail loudly at the call site — this is a client bug (missing/misspelled param), not a server state; fix the param construction instead of retrying.","preventionTips":["Centralize query-string building so params can't be silently dropped","Assert required params in a shared client wrapper","Watch for param-name typos (roleId vs role) when copying between endpoints"],"tags":["roles","validation","query-params","rest-api"],"backgroundTag":"missing-required-argument","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}