{"record":{"id":"703b623262734206","repo":"immich-app/immich","slug":"elevated-permission-is-required","errorCode":null,"errorMessage":"Elevated permission is required","messagePattern":"Elevated permission is required","errorType":"exception","errorClass":"UnauthorizedException","httpStatus":401,"severity":"error","filePath":"server/src/utils/access.ts","lineNumber":370,"sourceCode":"      return access.stack.checkOwnerAccess(auth.user.id, ids);\n    }\n\n    case Permission.WorkflowRead:\n    case Permission.WorkflowUpdate:\n    case Permission.WorkflowDelete:\n    case Permission.WorkflowLogs: {\n      return access.workflow.checkOwnerAccess(auth.user.id, ids);\n    }\n\n    default: {\n      return new Set<string>();\n    }\n  }\n};\n\nexport const requireElevatedPermission = (auth: AuthDto) => {\n  if (!auth.session?.hasElevatedPermission) {\n    throw new UnauthorizedException('Elevated permission is required');\n  }\n};\n","sourceCodeStart":352,"sourceCodeEnd":373,"githubUrl":"https://github.com/immich-app/immich/blob/e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c/server/src/utils/access.ts#L352-L373","documentation":"requireElevatedPermission guards endpoints that need a recently verified, elevated session. The AuthDto's session must carry hasElevatedPermission; if not, an UnauthorizedException (401) 'Elevated permission is required' is thrown. Elevated status is granted only after re-authentication (password confirmation) and typically expires.","triggerScenarios":"Calling a sensitive endpoint (e.g. changing password, downloading/ exporting sensitive data) with a session that never confirmed the password recently or whose elevated window has lapsed.","commonSituations":"Long-lived sessions/API keys without an elevated grant; automation scripts hitting protected endpoints without a password-reconfirmation step; user idling past the elevated-permission TTL then retrying an admin-style action.","solutions":["Re-authenticate to obtain an elevated session (confirm password via the appropriate endpoint) and retry the operation.","Log in again if the client cannot trigger re-confirmation.","For scripts, perform the elevated-confirmation call immediately before the protected call each run.","Check you are not using an API key/session type that cannot hold elevated permissions."],"exampleFix":"// before\nawait api.changePassword(dto); // 401: elevated permission required\n// after\nawait api.confirmPassword({ password }); // grants elevated session\nawait api.changePassword(dto);","handlingStrategy":"try-catch","validationCode":"// obtain an elevated session first\nawait api.confirmPassword({ password }); // 201 => session is elevated\n// then perform the protected call","typeGuard":null,"tryCatchPattern":"try {\n  await api.changePassword(dto);\n} catch (e) {\n  if (e instanceof UnauthorizedException && e.message === 'Elevated permission is required') {\n    await api.confirmPassword({ password });\n    await api.changePassword(dto); // retry once\n  } else {\n    throw e;\n  }\n}","preventionTips":["Always confirm password immediately before sensitive operations.","Detect 401 'Elevated permission is required' and prompt re-authentication in the client.","Avoid long idle periods between elevation and the protected call (TTL expiry).","Ensure automation scripts perform the confirmation step each run."],"tags":["authorization","session","elevated-permissions","reauthentication"],"backgroundTag":"authentication-required","analyzedSha":"e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}