RocketChat/Rocket.Chat · error · Meteor.Error

error-action-not-allowed

error-action-not-allowed

Error message

Deleting the rocket.cat user is not allowed

What it means

deleteUser throws error-action-not-allowed (method 'deleteUser', action 'Delete_user') when the target id is exactly 'rocket.cat', the built-in bot user. This is a hard-coded protection: the internal bot cannot be deleted because system messages and integrations depend on it.

Solutions

  1. Exclude 'rocket.cat' from any bulk deletion logic
  2. If the bot is unwanted, disable it via settings or remove the bot flag instead of deleting the user
  3. Guard the delete call: if (userId === 'rocket.cat') skip

Example fix

// before
for (const uid of allUserIds) {
  await deleteUser(uid);
}

// after
for (const uid of allUserIds) {
  if (uid === 'rocket.cat') continue;
  await deleteUser(uid);
}
Defensive patterns

Strategy: validation

Validate before calling

if (userId === 'rocket.cat') {
  throw new Error('The rocket.cat bot cannot be deleted');
}
await deleteUser(userId, confirmRelinquish);

Type guard

const isProtectedUserId = (id: string): boolean => id === 'rocket.cat';

Try / catch

try {
  await deleteUser(userId);
} catch (e) {
  if (isMeteorErrorCode(e, 'error-action-not-allowed') && userId === 'rocket.cat') {
  	skipProtectedAccount();
  }
}

Prevention

When it happens

Trigger: Admin UI 'delete user' on the rocket.cat account, or REST/programmatic deletion with userId 'rocket.cat'; mass-deletion scripts iterating over all user ids without excluding it.

Common situations: Cleanup scripts that enumerate users and try to remove everything; automated tests creating/deleting users that accidentally include the bot's fixed id.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/c8d42947a2325f0c. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/lib/users/deleteUser.ts:36

import { getUserSingleOwnedRooms } from './getUserSingleOwnedRooms';
import { settings } from '../../settings';
import { callbacks } from '../callbacks';
import { i18n } from '../i18n';
import { FileUpload } from '../media/file-upload';
import {
	notifyOnRoomChangedById,
	notifyOnIntegrationChangedByUserId,
	notifyOnLivechatDepartmentAgentChanged,
	notifyOnUserChange,
} from '../notifyListener';
import { getSubscribedRoomsForUserWithDetails, shouldRemoveOrChangeOwner } from '../rooms/getRoomsWithSingleOwner';
import { relinquishRoomOwnerships } from '../rooms/relinquishRoomOwnerships';
import { updateGroupDMsName } from '../rooms/updateGroupDMsName';

export async function deleteUser(userId: string, confirmRelinquish = false, deletedBy?: IUser['_id']): Promise<{ deletedRooms: string[] }> {
	if (userId === 'rocket.cat') {
		throw new Meteor.Error('error-action-not-allowed', 'Deleting the rocket.cat user is not allowed', {
			method: 'deleteUser',
			action: 'Delete_user',
		});
	}

	const user = await Users.findOneById(userId, {
		projection: { username: 1, avatarOrigin: 1, roles: 1, federated: 1 },
	});

	if (!user) {
		return { deletedRooms: [] };
	}

	if (isUserFederated(user)) {
		throw new Meteor.Error('error-not-allowed', 'User participated in federation, this user can only be deactivated permanently', {
			method: 'deleteUser',
		});
	}

View on GitHub (pinned to b2c16d5842)