RocketChat/Rocket.Chat · error · MeteorError

error-action-not-allowed

error-action-not-allowed

Error message

Notify ${mention} in this room not allowed

What it means

BeforeSavePreventMention checks the sender's permission for the given mention permission (e.g. mention-all / mention-here) in both global scope and room scope via Authorization.hasPermission. If neither grants it, the hook throws Meteor error-action-not-allowed with the hardcoded message 'Notify ${mention} in this room not allowed' (a localized action text is attached in the error details), stopping sendMessage.

Solutions

  1. Grant the role the relevant mention permission globally or on that room (Administration → Permissions)
  2. Remove the mention from the message text
  3. Route announcements through a user/role that holds the permission, or use a dedicated announcement mechanism
Defensive patterns

Strategy: validation

Validate before calling

import { Authorization } from '@rocket.chat/core-services';

const canMention =
  (await Authorization.hasPermission(uid, 'mention-all')) ||
  (await Authorization.hasPermission(uid, 'mention-all', rid));
if (!canMention) {
  msg = msg.replace(/@all|@here/g, '').trim(); // avoid the guaranteed rejection
}

Try / catch

try {
  await sendMessage(userId, { rid, msg });
} catch (err) {
  if (err?.error === 'error-action-not-allowed' && /Notify/.test(err?.message ?? '')) {
    // permission problem: tell the sender they lack the mention permission; do not retry as-is
    return notifyMissingPermission(userId, 'mention-all');
  }
  throw err;
}

Prevention

When it happens

Trigger: A user lacking the mention permission globally AND for that specific room sends a message containing @all/@here; the pre-save hook rejects it before persistence.

Common situations: Default roles without mention-all in large workspaces; bots/integrations posting as users who lack the permission; guests attempting @here.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/1932a62194f829a7. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/services/messages/hooks/BeforeSavePreventMention.ts:34

		permission: string;
	}): Promise<boolean> {
		if (!message.mentions?.some(({ _id }) => _id === mention)) {
			return true;
		}

		// Check if the user has permissions to use @all in both global and room scopes.
		if (await Authorization.hasPermission(message.u._id, permission)) {
			return true;
		}

		if (await Authorization.hasPermission(message.u._id, permission, message.rid)) {
			return true;
		}

		const action = i18n.t('Notify_all_in_this_room', { lng: user.language });

		// Also throw to stop propagation of 'sendMessage'.
		throw new MeteorError('error-action-not-allowed', `Notify ${mention} in this room not allowed`, {
			action,
		});
	}
}

View on GitHub (pinned to b2c16d5842)