RocketChat/Rocket.Chat · error · Meteor.Error

error-action-not-allowed

error-action-not-allowed

Error message

Mailing is not allowed

What it means

Thrown by POST /api/v1/rooms.export when the authenticated caller lacks the 'mail-messages' permission for the target room (hasPermissionAsync(this.user, 'mail-messages', rid) is false). It is the first check in the action, running before the room or user lookups, and guards both export modes (file and email).

Solutions

  1. Grant 'mail-messages' to the caller's role (Administration > Permissions), globally or scoped to the room
  2. Run the export as a user who already holds the permission (typically an admin)
  3. Catch this error and surface a permission request instead of retrying

Example fix

// before
await sdk.post('rooms.export', { rid, type: 'email', toUsers: ['me'], subject: 'log', messages: [] }); // as plain bot

// after
// admin grants mail-messages to the bot role, then:
await sdk.post('rooms.export', { rid, type: 'email', toUsers: ['me'], subject: 'log', messages: [] });
Defensive patterns

Strategy: try-catch

Try / catch

try {
  await sdk.post('rooms.export', { rid, type, ...payload });
} catch (e: any) {
  if (e?.response?.data?.errorType === 'error-action-not-allowed') {
    throw new Error('caller lacks mail-messages permission for this room — grant it and retry');
  }
  throw e;
}

Prevention

When it happens

Trigger: POST rooms.export as a regular user or a bot whose role has no 'mail-messages' permission; a room-scoped grant of mail-messages for a different rid; permission revoked after the integration was built.

Common situations: Custom export tools run with bot tokens that were never granted mail-messages; admins tightening permissions during audits breaking existing export jobs; role permission changes not propagated to room scope.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-08-18). Data as JSON: /api/errors/03027699c184d076. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/rooms.ts:1016

		response: {
			200: ajv.compile<void | { missing: string[] }>({
				type: 'object',
				properties: {
					success: { type: 'boolean', enum: [true] },
					missing: { type: 'array', items: { type: 'string' } },
				},
				required: ['success'],
				additionalProperties: false,
			}),
			400: validateBadRequestErrorResponse,
			401: validateUnauthorizedErrorResponse,
		},
	},
	async function action() {
		const { rid, type } = this.bodyParams;

		if (!(await hasPermissionAsync(this.user, 'mail-messages', rid))) {
			throw new Meteor.Error('error-action-not-allowed', 'Mailing is not allowed');
		}

		const room = await Rooms.findOneById(rid);
		if (!room) {
			throw new Meteor.Error('error-invalid-room');
		}

		const user = await Users.findOneById(this.userId);

		if (!user || !(await canAccessRoomAsync(room, user))) {
			throw new Meteor.Error('error-not-allowed', 'Not Allowed');
		}

		if (type === 'file') {
			const { dateFrom, dateTo } = this.bodyParams;
			const { format } = this.bodyParams;

			const convertedDateFrom = dateFrom ? new Date(dateFrom) : new Date(0);

View on GitHub (pinned to e4b8178b20)