RocketChat/Rocket.Chat · error

error-abac-not-enabled

error-abac-not-enabled

Error message

error-abac-not-enabled

What it means

Plain Error with message `error-abac-not-enabled` thrown by the POST abac/rooms/:rid/attributes endpoint when the ABAC_Enabled workspace setting is false at call time. The endpoint replaces ALL attributes of a room; the guard rejects the write before Abac.setRoomAbacAttributes runs. Comes back as a 400 to the REST caller.

Solutions

  1. Enable ABAC in Administration > Settings (ABAC_Enabled = true) with a valid enterprise license that includes the abac module.
  2. Verify the license covers ABAC; without it the setting cannot be enabled.
  3. Gate provisioning scripts on a settings check so they fail fast with a clear message instead of a 400.

Example fix

// before
await POST('abac/rooms/GENERAL/attributes', { attributes: ['dept:eng'] }); // 400

// after
await POST('settings/ABAC_Enabled', { value: true }); // one-time admin setup
await POST('abac/rooms/GENERAL/attributes', { attributes: ['dept:eng'] });
Defensive patterns

Strategy: validation

Validate before calling

const abacEnabled = async (): Promise<boolean> => {
	const { value } = await GET('settings/ABAC_Enabled')();
	return value === true;
};

Type guard

const isAbacNotEnabled = (error: unknown): boolean =>
	Boolean(error instanceof Error && error.message.includes('error-abac-not-enabled'));

Try / catch

try {
	await POST(`abac/rooms/${rid}/attributes`, { attributes });
} catch (error) {
	if (isAbacNotEnabled(error)) {
		throw new ConfigurationError('Enable ABAC_Enabled before writing room attributes');
	}
	throw error;
}

Prevention

When it happens

Trigger: POST /v1/abac/rooms/:rid/attributes with a full { attributes } payload while ABAC_Enabled is off — e.g. right after license activation but before enabling the feature.

Common situations: Automation calling ABAC endpoints before the admin toggled ABAC on; settings reset during workspace restore; toggling ABAC off while scripts still run.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/dcec340c339e1de7. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/ee/server/api/abac/index.ts:69

		'abac/rooms/:rid/attributes',
		{
			authRequired: true,
			permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
			body: POSTRoomAbacAttributesBodySchema,
			response: {
				200: GenericSuccessSchema,
				401: validateUnauthorizedErrorResponse,
				400: GenericErrorSchema,
				403: validateUnauthorizedErrorResponse,
			},
			license: ['abac'],
		},
		async function action() {
			const { rid } = this.urlParams;
			const { attributes } = this.bodyParams;

			if (!settings.get('ABAC_Enabled')) {
				throw new Error('error-abac-not-enabled');
			}

			// This is a replace-all operation
			// IF you need fine grained, use the other endpoints for removing, editing & adding single attributes
			await Abac.setRoomAbacAttributes(rid, attributes, getActorFromUser(this.user));
			return API.v1.success();
		},
	)
	.delete(
		'abac/rooms/:rid/attributes',
		{
			authRequired: true,
			permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
			response: {
				200: GenericSuccessSchema,
				401: validateUnauthorizedErrorResponse,
				400: GenericErrorSchema,
				403: validateUnauthorizedErrorResponse,

View on GitHub (pinned to b2c16d5842)