{"record":{"id":"d05be806bddab8d4","repo":"RocketChat/Rocket.Chat","slug":"error-invalid-user-d05be8","errorCode":"error-invalid-user","errorMessage":"There is no user with this username","messagePattern":"There is no user with this username","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/roles.ts","lineNumber":287,"sourceCode":"\t\t\t\t}),\n\t\t\t\t400: validateBadRequestErrorResponse,\n\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t\t403: validateForbiddenErrorResponse,\n\t\t\t},\n\t\t},\n\t\tasync function action() {\n\t\t\tconst { bodyParams } = this;\n\n\t\t\tconst { roleId, username, scope } = bodyParams;\n\n\t\t\tif (!roleId) {\n\t\t\t\treturn API.v1.failure('error-invalid-role-properties');\n\t\t\t}\n\n\t\t\tconst user = await Users.findOneByUsername(username);\n\n\t\t\tif (!user) {\n\t\t\t\tthrow new Meteor.Error('error-invalid-user', 'There is no user with this username');\n\t\t\t}\n\n\t\t\tconst role = await Roles.findOneById(roleId);\n\n\t\t\tif (!role) {\n\t\t\t\tthrow new Meteor.Error('error-invalid-roleId', 'This role does not exist');\n\t\t\t}\n\n\t\t\tif (!(await hasAnyRoleAsync(user._id, [role._id], scope))) {\n\t\t\t\tthrow new Meteor.Error('error-user-not-in-role', 'User is not in this role');\n\t\t\t}\n\n\t\t\tif (role._id === 'admin') {\n\t\t\t\tconst adminCount = await Roles.countUsersInRole('admin');\n\t\t\t\tif (adminCount === 1) {\n\t\t\t\t\tthrow new Meteor.Error('error-admin-required', 'You need to have at least one admin');\n\t\t\t\t}\n\t\t\t}","sourceCodeStart":269,"sourceCodeEnd":305,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/roles.ts#L269-L305","documentation":"Thrown by the POST roles.removeUserFromRole REST endpoint when Users.findOneByUsername(username) returns null, meaning no user document matches the username sent in the request body. The endpoint validates the user before it resolves the role, so a missing or mistyped username fails fast with HTTP 400 and errorType 'error-invalid-user'. The lookup is strictly by username, not by user _id.","triggerScenarios":"POST /api/v1/roles.removeUserFromRole with body { roleId, username } where username is a typo, belongs to a deleted user, or the caller mistakenly sent the user's _id instead of the username. Omitting the username field entirely also produces this error because findOneByUsername(undefined) resolves nothing.","commonSituations":"Automation scripts that store user IDs and send them as the username; users renamed or deleted between the initial fetch and the role call; provisioning imports where usernames differ from the source system; case mismatches or trailing whitespace, since the username match is exact.","solutions":["Verify the username first with GET /api/v1/users.info?username=<username> and only call removeUserFromRole when it returns a user","Send the account's username in the username body field, not the _id (fetch it from users.info if you only have an ID)","Trim whitespace and match username casing exactly against the stored user record","If the user was deleted, treat the role removal as unnecessary and skip the call instead of retrying"],"exampleFix":"// before\nawait sdk.post('roles.removeUserFromRole', { roleId: 'moderator', username: 'usr_8f3c2b' }); // _id passed as username -> error-invalid-user\n\n// after\nconst { user } = await sdk.get('users.info', { username });\nif (!user?.username) throw new Error(`no user '${username}'`);\nawait sdk.post('roles.removeUserFromRole', { roleId: 'moderator', username: user.username });","handlingStrategy":"validation","validationCode":"const { user } = await sdk.get('users.info', { username });\nif (!user?.username) throw new Error(`no user '${username}' — aborting role removal`);","typeGuard":null,"tryCatchPattern":"try {\n  await sdk.post('roles.removeUserFromRole', { roleId, username });\n} catch (e: any) {\n  if (e?.response?.data?.errorType === 'error-invalid-user') {\n    // user missing: verify username or treat as no-op\n    return;\n  }\n  throw e;\n}","preventionTips":["Keep a username -> id map fetched from users.info and always send the username field","Trim and case-normalize usernames before sending","Treat role-removal calls as idempotent: a missing user is an acceptable end state"],"tags":["roles","user-management","rest-api","validation"],"backgroundTag":"user-not-found","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}