immich-app/immich · error · BadRequestException

password is required

Error message

password is required

What it means

Thrown by UserAdminService.create when a new user is being created without a password while OAuth is the only enabled auth method... actually the inverse: OAuth is DISABLED and no password was supplied, so the account could never log in. A local (password) user requires a password, hence the 400 BadRequest.

Solutions

  1. Include a password in the create DTO when OAuth is disabled
  2. Enable OAuth in the server settings if users should authenticate via OAuth instead
  3. Have the user set a password via the password-reset flow after creation

Example fix

// before
await adminApi.createUser({ email: 'a@b.co', name: 'A' });
// after
await adminApi.createUser({ email: 'a@b.co', name: 'A', password: generateInitialPassword() });
Defensive patterns

Strategy: validation

Validate before calling

if (!oauthEnabled && !dto.password) {
  throw new Error('password is required when OAuth is disabled');
}

Try / catch

try { await adminApi.createUser(dto); } catch (e) {
  if (e.response?.status === 400 && /password is required/.test(e.response?.data?.message ?? '')) {
    return adminApi.createUser({ ...dto, password: generateInitialPassword() });
  }
  throw e;
}

Prevention

When it happens

Trigger: POST /api/admin/users (UserAdminService.create) with a UserAdminCreateDto lacking password while server config has oauth.enabled=false. Also occurs when the password field is dropped by a client serializer or when switching the server from OAuth to password auth without backfilling passwords.

Common situations: Server admin created users while OAuth was enabled, then disabled OAuth; automation scripts creating users without a password field; notify=true flows that assume users will set their own password.

Understand the failure class

Background: "missing required argument" and "the following required arguments were not provided": what required-argument errors mean and how to fix them — this error's family across 20 libraries.

Related errors


AI-assisted analysis of immich-app/immich@e55ac299a4 (2026-09-15). Data as JSON: /api/errors/08589e8ece7e1253. Report an issue: GitHub.

Appendix: source

Thrown at server/src/services/user-admin.service.ts:37

import { getCalendarHeatmap } from 'src/services/shared/user-methods.js';
import { findOrFail } from 'src/utils/misc.js';
import { getPreferences, getPreferencesPartial, mergePreferences } from 'src/utils/preferences.js';

@Injectable()
export class UserAdminService extends BaseService {
  async search(auth: AuthDto, dto: UserAdminSearchDto): Promise<UserAdminResponseDto[]> {
    const users = await this.userRepository.getList({
      id: dto.id,
      withDeleted: dto.withDeleted,
    });
    return users.map((user) => mapUserAdmin(user));
  }

  async create(dto: UserAdminCreateDto): Promise<UserAdminResponseDto> {
    const { notify, ...userDto } = dto;
    const config = await this.getConfig({ withCache: false });
    if (!config.oauth.enabled && !userDto.password) {
      throw new BadRequestException('password is required');
    }

    const user = await this.createUser(userDto);

    await this.eventRepository.emit('UserSignup', {
      notify: !!notify,
      id: user.id,
      password: userDto.password,
    });

    return mapUserAdmin(user);
  }

  async get(auth: AuthDto, id: string): Promise<UserAdminResponseDto> {
    const user = await this.findOrFail(id, { withDeleted: true });
    return mapUserAdmin(user);
  }

View on GitHub (pinned to e55ac299a4)