{"record":{"id":"d9d8a4b2939f5bcc","repo":"RocketChat/Rocket.Chat","slug":"error-token-param-not-provided","errorCode":null,"errorMessage":"error-token-param-not-provided","messagePattern":"error-token-param-not-provided","errorType":"exception","errorClass":"Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/omnichannel/message.ts","lineNumber":205,"sourceCode":"\t\t\t\t});\n\t\t\t}\n\n\t\t\treturn API.v1.failure();\n\t\t},\n\t},\n);\n\nAPI.v1.addRoute(\n\t'livechat/messages.history/:rid',\n\t{ validateParams: isGETLivechatMessagesHistoryRidParams },\n\t{\n\t\tasync get() {\n\t\t\tconst { offset } = await getPaginationItems(this.queryParams);\n\t\t\tconst { token } = this.queryParams;\n\t\t\tconst { rid } = this.urlParams;\n\n\t\t\tif (!token) {\n\t\t\t\tthrow new Error('error-token-param-not-provided');\n\t\t\t}\n\n\t\t\tconst guest = await findGuest(token);\n\t\t\tif (!guest) {\n\t\t\t\tthrow new Error('invalid-token');\n\t\t\t}\n\n\t\t\tconst room = await findRoom(token, rid);\n\t\t\tif (!room) {\n\t\t\t\tthrow new Error('invalid-room');\n\t\t\t}\n\n\t\t\tlet ls = undefined;\n\t\t\tif (this.queryParams.ls) {\n\t\t\t\tls = new Date(this.queryParams.ls);\n\t\t\t}\n\n\t\t\tlet end = undefined;","sourceCodeStart":187,"sourceCodeEnd":223,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/omnichannel/message.ts#L187-L223","documentation":"Thrown by GET /api/v1/livechat/messages.history/:rid when the token query parameter is entirely absent. This is an explicit hand-rolled guard (the AJV schema isGETLivechatMessagesHistoryRidParams evidently permits an omitted token, so the handler checks it itself). It is a malformed-request error, distinct from 'invalid-token' which means 'token present but unknown'.","triggerScenarios":"GET /api/v1/livechat/messages.history/<rid> with no ?token= query parameter at all, or a URL where the query string got dropped (unencoded template, trailing fragment, redirect stripping the query).","commonSituations":"Building the history URL by concatenating path segments only; a reverse proxy or SPA router stripping query strings on redirect; the widget mounting history before the visitor registration completed and the token exists.","solutions":["Always append ?token=<visitorToken> (and use encodeURIComponent) when calling the history endpoint.","Ensure the visitor registration step has completed and the token is available before loading history.","If behind a proxy/CDN, verify query strings survive redirects to the API route."],"exampleFix":"// before (query string never appended)\nconst res = await fetch(`${baseUrl}/api/v1/livechat/messages.history/${rid}`);\n\n// after (required token param included and encoded)\nconst res = await fetch(`${baseUrl}/api/v1/livechat/messages.history/${rid}?token=${encodeURIComponent(token)}`);","handlingStrategy":"validation","validationCode":"// Build the history URL with required params up front\nfunction historyUrl(baseUrl: string, rid: string, token: string): string {\n  if (!token) throw new Error('visitor token missing; register before loading history');\n  return `${baseUrl}/api/v1/livechat/messages.history/${encodeURIComponent(rid)}?token=${encodeURIComponent(token)}`;\n}","typeGuard":null,"tryCatchPattern":"if (isLivechatErrorResponse(body) && body.error === 'error-token-param-not-provided') {\n  throw new Error('programmer error: history URL built without token'); // fail loudly, it is a client bug\n}","preventionTips":["Centralize URL building in a typed client so token can never be omitted from query-string routes.","Ensure registration completes (token in hand) before any history fetch.","Verify proxies/redirects preserve query strings on API paths."],"tags":["livechat","omnichannel","missing-parameter","rest-api","query-params"],"backgroundTag":"missing-required-argument","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}