RocketChat/Rocket.Chat · error · Meteor.Error
error-action-not-allowed
error-action-not-allowed
Error message
Mailing is not allowed
What it means
Thrown by POST /api/v1/rooms.export when the authenticated caller lacks the 'mail-messages' permission for the target room (hasPermissionAsync(this.user, 'mail-messages', rid) is false). It is the first check in the action, running before the room or user lookups, and guards both export modes (file and email).
Solutions
- Grant 'mail-messages' to the caller's role (Administration > Permissions), globally or scoped to the room
- Run the export as a user who already holds the permission (typically an admin)
- Catch this error and surface a permission request instead of retrying
Example fix
// before
await sdk.post('rooms.export', { rid, type: 'email', toUsers: ['me'], subject: 'log', messages: [] }); // as plain bot
// after
// admin grants mail-messages to the bot role, then:
await sdk.post('rooms.export', { rid, type: 'email', toUsers: ['me'], subject: 'log', messages: [] }); Defensive patterns
Strategy: try-catch
Try / catch
try {
await sdk.post('rooms.export', { rid, type, ...payload });
} catch (e: any) {
if (e?.response?.data?.errorType === 'error-action-not-allowed') {
throw new Error('caller lacks mail-messages permission for this room — grant it and retry');
}
throw e;
} Prevention
- Grant mail-messages to service accounts at provisioning time, not on failure
- Run export jobs with tokens whose permissions you control
- Audit role permissions after workspace permission sweeps
When it happens
Trigger: POST rooms.export as a regular user or a bot whose role has no 'mail-messages' permission; a room-scoped grant of mail-messages for a different rid; permission revoked after the integration was built.
Common situations: Custom export tools run with bot tokens that were never granted mail-messages; admins tightening permissions during audits breaking existing export jobs; role permission changes not propagated to room scope.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
Related errors
- error-not-allowed
- error-not-authorized
- error-action-not-allowed
- error-cannot-delete-team-channel
- error-invalid-dates
AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-08-18).
Data as JSON: /api/errors/03027699c184d076.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/rooms.ts:1016
response: {
200: ajv.compile<void | { missing: string[] }>({
type: 'object',
properties: {
success: { type: 'boolean', enum: [true] },
missing: { type: 'array', items: { type: 'string' } },
},
required: ['success'],
additionalProperties: false,
}),
400: validateBadRequestErrorResponse,
401: validateUnauthorizedErrorResponse,
},
},
async function action() {
const { rid, type } = this.bodyParams;
if (!(await hasPermissionAsync(this.user, 'mail-messages', rid))) {
throw new Meteor.Error('error-action-not-allowed', 'Mailing is not allowed');
}
const room = await Rooms.findOneById(rid);
if (!room) {
throw new Meteor.Error('error-invalid-room');
}
const user = await Users.findOneById(this.userId);
if (!user || !(await canAccessRoomAsync(room, user))) {
throw new Meteor.Error('error-not-allowed', 'Not Allowed');
}
if (type === 'file') {
const { dateFrom, dateTo } = this.bodyParams;
const { format } = this.bodyParams;
const convertedDateFrom = dateFrom ? new Date(dateFrom) : new Date(0);View on GitHub (pinned to e4b8178b20)