{"record":{"id":"c05872e653fbd49d","repo":"immich-app/immich","slug":"cannot-grant-permissions-you-do-not-have","errorCode":null,"errorMessage":"Cannot grant permissions you do not have","messagePattern":"Cannot grant permissions you do not have","errorType":"exception","errorClass":"BadRequestException","httpStatus":400,"severity":"error","filePath":"server/src/services/api-key.service.ts","lineNumber":17,"sourceCode":"import { BadRequestException, ForbiddenException, Injectable } from '@nestjs/common';\nimport { ApiKey } from 'src/database.js';\nimport { ApiKeyCreateDto, ApiKeyCreateResponseDto, ApiKeyResponseDto, ApiKeyUpdateDto } from 'src/dtos/api-key.dto.js';\nimport { AuthDto } from 'src/dtos/auth.dto.js';\nimport { Permission } from 'src/enum.js';\nimport { BaseService } from 'src/services/base.service.js';\nimport { isGranted } from 'src/utils/access.js';\nimport { findOrFail } from 'src/utils/misc.js';\n\n@Injectable()\nexport class ApiKeyService extends BaseService {\n  async create(auth: AuthDto, dto: ApiKeyCreateDto): Promise<ApiKeyCreateResponseDto> {\n    const token = this.cryptoRepository.randomBytesAsText(32);\n    const hashed = this.cryptoRepository.hashSha256(token);\n\n    if (auth.apiKey && !isGranted({ requested: dto.permissions, current: auth.apiKey.permissions })) {\n      throw new BadRequestException('Cannot grant permissions you do not have');\n    }\n\n    const entity = await this.apiKeyRepository.create({\n      key: hashed,\n      name: dto.name || 'API Key',\n      userId: auth.user.id,\n      permissions: dto.permissions,\n    });\n    const apiKey = this.map(entity);\n\n    return { ...apiKey, secret: token, apiKey };\n  }\n\n  async update(auth: AuthDto, id: string, dto: ApiKeyUpdateDto): Promise<ApiKeyResponseDto> {\n    const exists = await this.apiKeyRepository.getById(auth.user.id, id);\n    if (!exists) {\n      throw new BadRequestException('API Key not found');\n    }","sourceCodeStart":1,"sourceCodeEnd":35,"githubUrl":"https://github.com/immich-app/immich/blob/e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c/server/src/services/api-key.service.ts#L1-L35","documentation":"Raised by ApiKeyService.create when the current request is itself authenticated with an API key and the requested permissions in ApiKeyCreateDto are not a subset of that key's own permissions (checked with isGranted). An API key cannot mint another key with privileges beyond its own, so creation is refused with a 400. The input at fault is dto.permissions.","triggerScenarios":"Thrown at server/src/services/api-key.service.ts:17 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Remove the excess permissions from dto.permissions so they are a subset of the authenticating API key's permissions","Authenticate as the user (session/OAuth) instead of via the restricted API key, then create the new key"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}