immich-app/immich · error · BadRequestException
password is required
Error message
password is required
What it means
Thrown by UserAdminService.create when a new user is being created without a password while OAuth is the only enabled auth method... actually the inverse: OAuth is DISABLED and no password was supplied, so the account could never log in. A local (password) user requires a password, hence the 400 BadRequest.
Solutions
- Include a password in the create DTO when OAuth is disabled
- Enable OAuth in the server settings if users should authenticate via OAuth instead
- Have the user set a password via the password-reset flow after creation
Example fix
// before
await adminApi.createUser({ email: 'a@b.co', name: 'A' });
// after
await adminApi.createUser({ email: 'a@b.co', name: 'A', password: generateInitialPassword() }); Defensive patterns
Strategy: validation
Validate before calling
if (!oauthEnabled && !dto.password) {
throw new Error('password is required when OAuth is disabled');
} Try / catch
try { await adminApi.createUser(dto); } catch (e) {
if (e.response?.status === 400 && /password is required/.test(e.response?.data?.message ?? '')) {
return adminApi.createUser({ ...dto, password: generateInitialPassword() });
}
throw e;
} Prevention
- Check server OAuth settings before automating user creation
- Always generate an initial password in admin scripts
- Re-check config after switching auth methods (OAuth on/off)
When it happens
Trigger: POST /api/admin/users (UserAdminService.create) with a UserAdminCreateDto lacking password while server config has oauth.enabled=false. Also occurs when the password field is dropped by a client serializer or when switching the server from OAuth to password auth without backfilling passwords.
Common situations: Server admin created users while OAuth was enabled, then disabled OAuth; automation scripts creating users without a password field; notify=true flows that assume users will set their own password.
Understand the failure class
Background: "missing required argument" and "the following required arguments were not provided": what required-argument errors mean and how to fix them — this error's family across 20 libraries.
Related errors
- error instanceof Error ? error.message : error
- {error.message}
- Invalid environment variables:
- Invalid system config:
- Invalid system config
AI-assisted analysis of immich-app/immich@e55ac299a4 (2026-09-15).
Data as JSON: /api/errors/08589e8ece7e1253.
Report an issue: GitHub.
Appendix: source
Thrown at server/src/services/user-admin.service.ts:37
import { getCalendarHeatmap } from 'src/services/shared/user-methods.js';
import { findOrFail } from 'src/utils/misc.js';
import { getPreferences, getPreferencesPartial, mergePreferences } from 'src/utils/preferences.js';
@Injectable()
export class UserAdminService extends BaseService {
async search(auth: AuthDto, dto: UserAdminSearchDto): Promise<UserAdminResponseDto[]> {
const users = await this.userRepository.getList({
id: dto.id,
withDeleted: dto.withDeleted,
});
return users.map((user) => mapUserAdmin(user));
}
async create(dto: UserAdminCreateDto): Promise<UserAdminResponseDto> {
const { notify, ...userDto } = dto;
const config = await this.getConfig({ withCache: false });
if (!config.oauth.enabled && !userDto.password) {
throw new BadRequestException('password is required');
}
const user = await this.createUser(userDto);
await this.eventRepository.emit('UserSignup', {
notify: !!notify,
id: user.id,
password: userDto.password,
});
return mapUserAdmin(user);
}
async get(auth: AuthDto, id: string): Promise<UserAdminResponseDto> {
const user = await this.findOrFail(id, { withDeleted: true });
return mapUserAdmin(user);
}
View on GitHub (pinned to e55ac299a4)