RocketChat/Rocket.Chat · error
error-abac-not-enabled
error-abac-not-enabled
Error message
error-abac-not-enabled
What it means
Plain Error with message `error-abac-not-enabled` thrown by the POST abac/rooms/:rid/attributes endpoint when the ABAC_Enabled workspace setting is false at call time. The endpoint replaces ALL attributes of a room; the guard rejects the write before Abac.setRoomAbacAttributes runs. Comes back as a 400 to the REST caller.
Solutions
- Enable ABAC in Administration > Settings (ABAC_Enabled = true) with a valid enterprise license that includes the abac module.
- Verify the license covers ABAC; without it the setting cannot be enabled.
- Gate provisioning scripts on a settings check so they fail fast with a clear message instead of a 400.
Example fix
// before
await POST('abac/rooms/GENERAL/attributes', { attributes: ['dept:eng'] }); // 400
// after
await POST('settings/ABAC_Enabled', { value: true }); // one-time admin setup
await POST('abac/rooms/GENERAL/attributes', { attributes: ['dept:eng'] }); Defensive patterns
Strategy: validation
Validate before calling
const abacEnabled = async (): Promise<boolean> => {
const { value } = await GET('settings/ABAC_Enabled')();
return value === true;
}; Type guard
const isAbacNotEnabled = (error: unknown): boolean =>
Boolean(error instanceof Error && error.message.includes('error-abac-not-enabled')); Try / catch
try {
await POST(`abac/rooms/${rid}/attributes`, { attributes });
} catch (error) {
if (isAbacNotEnabled(error)) {
throw new ConfigurationError('Enable ABAC_Enabled before writing room attributes');
}
throw error;
} Prevention
- Run setup in order: license -> ABAC_Enabled -> attribute writes.
- Preflight the setting in scripts instead of relying on the 400.
- Remember this call replaces ALL room attributes — snapshot first when enabled.
When it happens
Trigger: POST /v1/abac/rooms/:rid/attributes with a full { attributes } payload while ABAC_Enabled is off — e.g. right after license activation but before enabling the feature.
Common situations: Automation calling ABAC endpoints before the admin toggled ABAC on; settings reset during workspace restore; toggling ABAC off while scripts still run.
Related errors
- error-abac-attribute-store-external
- LDAP_disabled
- error-action-not-allowed
- error-invalid-user
- error-not-authorized
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/dcec340c339e1de7.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/ee/server/api/abac/index.ts:69
'abac/rooms/:rid/attributes',
{
authRequired: true,
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
body: POSTRoomAbacAttributesBodySchema,
response: {
200: GenericSuccessSchema,
401: validateUnauthorizedErrorResponse,
400: GenericErrorSchema,
403: validateUnauthorizedErrorResponse,
},
license: ['abac'],
},
async function action() {
const { rid } = this.urlParams;
const { attributes } = this.bodyParams;
if (!settings.get('ABAC_Enabled')) {
throw new Error('error-abac-not-enabled');
}
// This is a replace-all operation
// IF you need fine grained, use the other endpoints for removing, editing & adding single attributes
await Abac.setRoomAbacAttributes(rid, attributes, getActorFromUser(this.user));
return API.v1.success();
},
)
.delete(
'abac/rooms/:rid/attributes',
{
authRequired: true,
permissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],
response: {
200: GenericSuccessSchema,
401: validateUnauthorizedErrorResponse,
400: GenericErrorSchema,
403: validateUnauthorizedErrorResponse,View on GitHub (pinned to b2c16d5842)