{"record":{"id":"e9a767ec52f55f2f","repo":"RocketChat/Rocket.Chat","slug":"invalid-message-id-e9a767","errorCode":null,"errorMessage":"Invalid message id","messagePattern":"Invalid message id","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"apps/meteor/app/apps/server/bridges/moderation.ts","lineNumber":18,"sourceCode":"import type { IAppServerOrchestrator } from '@rocket.chat/apps';\nimport { ModerationBridge } from '@rocket.chat/apps/dist/server/bridges/ModerationBridge';\nimport type { IMessage } from '@rocket.chat/apps-engine/definition/messages';\nimport type { IUser } from '@rocket.chat/apps-engine/definition/users';\nimport { ModerationReports } from '@rocket.chat/models';\n\nimport { reportMessage } from '../../../../server/lib/moderation/reportMessage';\n\nexport class AppModerationBridge extends ModerationBridge {\n\tconstructor(private readonly orch: IAppServerOrchestrator) {\n\t\tsuper();\n\t}\n\n\tprotected async report(messageId: IMessage['id'], description: string, userId: string, appId: string): Promise<void> {\n\t\tthis.orch.debugLog(`The App ${appId} is creating a new report.`);\n\n\t\tif (!messageId) {\n\t\t\tthrow new Error('Invalid message id');\n\t\t}\n\n\t\tif (!description) {\n\t\t\tthrow new Error('Invalid description');\n\t\t}\n\n\t\tawait reportMessage(messageId, description, userId || 'rocket.cat');\n\t}\n\n\tprotected async dismissReportsByMessageId(messageId: IMessage['id'], reason: string, action: string, appId: string): Promise<void> {\n\t\tthis.orch.debugLog(`The App ${appId} is dismissing reports by message id.`);\n\n\t\tif (!messageId) {\n\t\t\tthrow new Error('Invalid message id');\n\t\t}\n\n\t\tawait ModerationReports.hideMessageReportsByMessageId(messageId, appId, reason, action);\n\t}","sourceCodeStart":1,"sourceCodeEnd":36,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/app/apps/server/bridges/moderation.ts#L1-L36","documentation":"AppModerationBridge.report throws when the messageId passed to the moderation report API is falsy (undefined, null, ''). Reports must attach to an existing persisted message, so the bridge validates the id before calling reportMessage(messageId, description, userId || 'rocket.cat').","triggerScenarios":"An app calls the moderation report API with a message object that was built locally and never persisted (no id), with a destructured/misspelled field that yields undefined, or with an empty string from untrusted input.","commonSituations":"Reporting messages received from webhooks or external systems where the id field is named differently; passing message.id of a draft/unsent message; id lost through JSON round-trips.","solutions":["Ensure the message was sent/persisted first and pass its real id (e.g. obtained from the message reader)","Load the message via the reader (getMessageById) and use the loaded id","Guard the call: skip or prompt when !messageId","Check the property name on your message object (id vs _id)"],"exampleFix":"// before\nawait app.getRocketChat().getModeration().reportMessage(msg?.id, description, userId); // msg?.id undefined -> throws\n// after\nif (!msg?.id) throw new Error('cannot report a message without an id');\nawait app.getRocketChat().getModeration().reportMessage(msg.id, description, userId);","handlingStrategy":"validation","validationCode":"const reportMessage = async (messageId: unknown, description: string, userId: string) => {\n  if (typeof messageId !== 'string' || messageId.trim() === '') {\n    throw new Error('cannot report a message without a persisted id');\n  }\n  await app.getRocketChat().getModeration().reportMessage(messageId, description, userId);\n};","typeGuard":"const hasMessageId = (m: unknown): m is { id: string } =>\n  typeof m === 'object' && m !== null && typeof (m as { id?: unknown }).id === 'string' && (m as { id: string }).id.length > 0;\n\nif (!hasMessageId(msg)) return;","tryCatchPattern":"try {\n  await app.getRocketChat().getModeration().reportMessage(messageId, description, userId);\n} catch (err) {\n  if (err instanceof Error && err.message === 'Invalid message id') {\n    app.getLogger().warn('report skipped: no message id');\n    return;\n  }\n  throw err;\n}","preventionTips":["Only report messages obtained from the message reader or live events (they carry ids","Map external system ids to Rocket.Chat message ids before reporting","Check for id vs _id naming when handling raw core objects","Skip early with a log instead of calling the API with undefined"],"tags":["apps-engine","moderation","report","validation","missing-id"],"backgroundTag":"missing-required-argument","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}