{"record":{"id":"a748c7558f6854e1","repo":"RocketChat/Rocket.Chat","slug":"invalid-user-id-a748c7","errorCode":null,"errorMessage":"Invalid user id","messagePattern":"Invalid user id","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"apps/meteor/app/apps/server/bridges/users.ts","lineNumber":170,"sourceCode":"\t\t\t);\n\t\t}\n\n\t\tif (!Object.keys(updateFields).length) {\n\t\t\treturn true;\n\t\t}\n\n\t\tawait Users.updateOne({ _id: user.id }, { $set: updateFields as any });\n\n\t\tvoid notifyOnUserChange({ clientAction: 'updated', id: user.id, diff: updateFields });\n\n\t\treturn true;\n\t}\n\n\tprotected async deactivate(userId: IUser['id'], confirmRelinquish: boolean, appId: string): Promise<boolean> {\n\t\tthis.orch.debugLog(`The App ${appId} is deactivating a user.`);\n\n\t\tif (!userId) {\n\t\t\tthrow new Error('Invalid user id');\n\t\t}\n\n\t\t// #TODO: #AppsEngineTypes - Remove explicit types and typecasts once the apps-engine definition/implementation mismatch is fixed.\n\t\tconst convertedUser: IUser | undefined = await this.orch.getConverters()?.get('users').convertById(userId);\n\t\tconst { id: uid } = convertedUser as IUser;\n\n\t\tawait setUserActiveStatus(uid, false, confirmRelinquish);\n\n\t\treturn true;\n\t}\n\n\tprotected async setActiveState(\n\t\tuserId: IUser['id'],\n\t\tstate: Pick<IUser, 'statusDefault' | 'statusSource' | 'statusText' | 'statusExpiresAt' | 'statusId'>,\n\t\tappId: string,\n\t): Promise<void> {\n\t\tthis.orch.debugLog(`The App ${appId} is setting active state for user ${userId}`);\n","sourceCodeStart":152,"sourceCodeEnd":188,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/app/apps/server/bridges/users.ts#L152-L188","documentation":"deactivate on the users bridge requires a non-empty user id; an empty string or undefined fails with 'Invalid user id' before any lookup. Deactivation has no meaning without a target, and the server treats a blank id as a programming error rather than missing data.","triggerScenarios":"App calls deactivate with an id from an unset variable, an optional parameter defaulting to '', or reads .id off an undefined user object after a failed lookup.","commonSituations":"UIKit action handlers with optional data fields; user-picker UI where nothing was selected; refactors dropping the id assignment.","solutions":["Source the id from a fetched user object and check it is a non-empty string.","Return early from the handler when no target user was selected.","If the user may already be gone, check existence first and treat it as a no-op."],"exampleFix":"// before\nawait deactivate(selectedUserId ?? '', confirmRelinquish, appId);\n\n// after\nif (!selectedUserId) {\n  return { error: 'Select a user to deactivate' };\n}\nawait deactivate(selectedUserId, confirmRelinquish, appId);","handlingStrategy":"validation","validationCode":"if (!userId || userId.trim() === '') {\n  return { error: 'A valid user id is required' };\n}","typeGuard":"const isNonEmptyString = (v: unknown): v is string =>\n  typeof v === 'string' && v.trim().length > 0;","tryCatchPattern":null,"preventionTips":["Validate ids at handler entry, especially from optional UI fields.","Read ids from fetched user objects, not raw interaction params.","Treat missing selection as a no-op, not an error path."],"tags":["apps-engine","users","parameter-validation","deactivation"],"backgroundTag":"missing-required-argument","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}