{"record":{"id":"c19afbe7dea57b9f","repo":"RocketChat/Rocket.Chat","slug":"user-not-provided","errorCode":null,"errorMessage":"User not provided","messagePattern":"User not provided","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"apps/meteor/app/apps/server/bridges/users.ts","lineNumber":134,"sourceCode":"\t\t// It's actually not a problem if there is no App user to delete - just means we don't need to do anything more.\n\t\tif (!user) {\n\t\t\treturn true;\n\t\t}\n\n\t\ttry {\n\t\t\tawait deleteUser(user.id);\n\t\t} catch (err) {\n\t\t\tthrow new Error(`Errors occurred while deleting an app user: ${err}`);\n\t\t}\n\n\t\treturn true;\n\t}\n\n\tprotected async update(user: IUser & { id: string }, fields: Partial<IUser>, appId: string): Promise<boolean> {\n\t\tthis.orch.debugLog(`The App ${appId} is updating a user`);\n\n\t\tif (!user) {\n\t\t\tthrow new Error('User not provided');\n\t\t}\n\n\t\tconst { status, statusText, ...updateFields } = fields;\n\n\t\tif (status) {\n\t\t\tawait Presence.setStatus(user.id, status as UserStatus, statusText);\n\t\t} else if (typeof statusText === 'string') {\n\t\t\tawait setStatusText(\n\t\t\t\t{\n\t\t\t\t\t_id: user.id,\n\t\t\t\t\tusername: user.username,\n\t\t\t\t\tname: user.name,\n\t\t\t\t\tstatus: user.status as UserStatus,\n\t\t\t\t\troles: user.roles,\n\t\t\t\t\tstatusText: user.statusText,\n\t\t\t\t},\n\t\t\t\tstatusText,\n\t\t\t);","sourceCodeStart":116,"sourceCodeEnd":152,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/app/apps/server/bridges/users.ts#L116-L152","documentation":"The users bridge update refuses to proceed when the user argument is falsy. The call requires the existing user object (at minimum its id); passing undefined/null — often from an optional lookup that returned nothing — trips this guard before any field is written.","triggerScenarios":"App calls user update with a variable produced by a lookup that returned undefined (user gone, wrong id); destructuring a missing parameter; updating a user before it was created.","commonSituations":"Optional-chained lookups not guarded; app updating its bot user before the framework created it; races with uninstall removing the user mid-flow.","solutions":["Fetch the user first (by id via the user reader) and abort when not found.","Guard at the call site: if (!user) return; before updating.","Ensure the user exists (bot/app creation) before attempting updates."],"exampleFix":"// before\nawait updateUser(maybeUser, fields, appId); // maybeUser may be undefined\n\n// after\nif (!user) {\n  throw new Error('Cannot update a user that does not exist');\n}\nawait updateUser(user, fields, appId);","handlingStrategy":"validation","validationCode":"if (!user || !user.id) {\n  // nothing to update\n  return;\n}","typeGuard":"const isExistingUser = (u: IUser | null | undefined): u is IUser & { id: string } =>\n  Boolean(u && u.id);","tryCatchPattern":null,"preventionTips":["Fetch-then-guard: never forward optional lookup results into update.","Create the (bot) user before updating it.","Log which user failed when guarding at the boundary."],"tags":["apps-engine","users","parameter-validation"],"backgroundTag":"missing-required-argument","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}