payloadcms/payload · error · Error
Unauthorized
Error message
Unauthorized
What it means
The render-widget server function throws `Error('Unauthorized')` when `req.user` is absent. On-demand widget rendering is an authenticated admin operation that reads dashboard widget configs and the request's locale, so anonymous requests are rejected before any widget is located or rendered.
Source
Thrown at packages/ui/src/views/Dashboard/Default/ModularDashboard/renderWidget/renderWidgetServerFn.ts:32
* The slug of the widget to render
*/
widgetSlug: string
}
export type RenderWidgetServerFnReturnType = {
component: React.ReactNode
}
/**
* Server function to render a widget on-demand.
* Similar to render-field but specifically for dashboard widgets.
*/
export const renderWidgetHandler: ServerFunction<
RenderWidgetServerFnArgs,
RenderWidgetServerFnReturnType
> = ({ cookies, locale, permissions, req, widgetData, widgetSlug }) => {
if (!req.user) {
throw new Error('Unauthorized')
}
const { widgets } = req.payload.config.admin.dashboard
const { importMap } = req.payload
// Find the widget configuration
const widgetConfig = widgets.find((widget) => widget.slug === widgetSlug)
if (!widgetConfig) {
return {
component: React.createElement(
'div',
{
style: {
background: 'var(--color-bg-secondary)',
border: 'var(--stroke-width-small) solid var(--color-border)',
borderRadius: 'var(--radius-medium)',
color: 'var(--color-text)',View on GitHub (pinned to 00c58b35c0)
Solutions
- Ensure the user is logged in before widgets attempt to render on demand.
- Confirm the auth cookie is forwarded with the render-widget request.
- Verify the auth strategy populates `req.user` for admin routes.
- Re-authenticate and retry; note a missing widget returns a friendly placeholder, but a missing user throws.
Defensive patterns
Strategy: validation
Validate before calling
if (!req.user) {
// skip on-demand widget render or prompt re-login
} Type guard
function isAuthenticated<
R extends { user?: unknown },
>(req: R): req is R & { user: NonNullable<R['user']> } {
return !!req.user
} Try / catch
try {
await renderWidget(args)
} catch (err) {
if (err instanceof Error && err.message === 'Unauthorized') {
// prompt re-login; widget render can be retried once authenticated
} else {
throw err
}
} Prevention
- Forward the auth cookie with all render-widget requests.
- Re-check the session before triggering on-demand widget renders.
- Confirm the auth strategy populates `req.user` for admin routes.
- Distinguish this auth error from a missing-widget placeholder response.
When it happens
Trigger: Dashboard widget render fired after session timeout, programmatic widget rendering without an authenticated session, auth cookie not forwarded to the server function, custom auth strategy that does not set `req.user`.
Common situations: Idle sessions that lapse during dashboard use, cross-origin widget requests without credentials, auth misconfiguration, proxies stripping cookies.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Unauthorized
- Unauthorized, you must be logged in to make this request.
- Unauthorized
- Unauthorized
- Unauthorized, you must be logged in to make this request.
AI-assisted analysis of payloadcms/payload@00c58b35c0 (2026-08-12).
Data as JSON: /api/errors/6c1f473a85c4a15f.
Report an issue: GitHub.