RocketChat/Rocket.Chat · error · MeteorError
error-action-not-allowed
error-action-not-allowed
Error message
Notify ${mention} in this room not allowed What it means
BeforeSavePreventMention checks the sender's permission for the given mention permission (e.g. mention-all / mention-here) in both global scope and room scope via Authorization.hasPermission. If neither grants it, the hook throws Meteor error-action-not-allowed with the hardcoded message 'Notify ${mention} in this room not allowed' (a localized action text is attached in the error details), stopping sendMessage.
Solutions
- Grant the role the relevant mention permission globally or on that room (Administration → Permissions)
- Remove the mention from the message text
- Route announcements through a user/role that holds the permission, or use a dedicated announcement mechanism
Defensive patterns
Strategy: validation
Validate before calling
import { Authorization } from '@rocket.chat/core-services';
const canMention =
(await Authorization.hasPermission(uid, 'mention-all')) ||
(await Authorization.hasPermission(uid, 'mention-all', rid));
if (!canMention) {
msg = msg.replace(/@all|@here/g, '').trim(); // avoid the guaranteed rejection
} Try / catch
try {
await sendMessage(userId, { rid, msg });
} catch (err) {
if (err?.error === 'error-action-not-allowed' && /Notify/.test(err?.message ?? '')) {
// permission problem: tell the sender they lack the mention permission; do not retry as-is
return notifyMissingPermission(userId, 'mention-all');
}
throw err;
} Prevention
- Check mention permissions (global and room-scoped) before sending @all/@here
- Hide/disable mention-all UI for roles without the permission
- Route broadcasts through accounts that hold the permission
When it happens
Trigger: A user lacking the mention permission globally AND for that specific room sends a message containing @all/@here; the pre-save hook rejects it before persistence.
Common situations: Default roles without mention-all in large workspaces; bots/integrations posting as users who lack the permission; guests attempting @here.
Related errors
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/1932a62194f829a7.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/services/messages/hooks/BeforeSavePreventMention.ts:34
permission: string;
}): Promise<boolean> {
if (!message.mentions?.some(({ _id }) => _id === mention)) {
return true;
}
// Check if the user has permissions to use @all in both global and room scopes.
if (await Authorization.hasPermission(message.u._id, permission)) {
return true;
}
if (await Authorization.hasPermission(message.u._id, permission, message.rid)) {
return true;
}
const action = i18n.t('Notify_all_in_this_room', { lng: user.language });
// Also throw to stop propagation of 'sendMessage'.
throw new MeteorError('error-action-not-allowed', `Notify ${mention} in this room not allowed`, {
action,
});
}
}
View on GitHub (pinned to b2c16d5842)