RocketChat/Rocket.Chat · error · Meteor.Error
error-not-allowed
error-not-allowed
Error message
Not allowed
What it means
The removeCannedResponse method (apps/meteor/ee/server/meteor-methods/removeCannedResponse.ts:10) first checks hasPermissionAsync(uid, 'remove-canned-responses'); users without that permission get Meteor.Error('error-not-allowed') before the id is even validated.
Solutions
- Grant 'remove-canned-responses' to the acting user's role (Administration > Permissions)
- Pre-check permission client-side to hide delete actions the user cannot perform
- Use an admin/manager account for bulk cleanup of canned responses
Example fix
// before
Meteor.call('removeCannedResponse', _id);
// after
if (!(await hasPermissionAsync(uid, 'remove-canned-responses'))) {
throw new Meteor.Error('error-not-allowed', 'Not allowed');
}
Meteor.call('removeCannedResponse', _id); Defensive patterns
Strategy: validation
Validate before calling
if (!(await hasPermissionAsync(uid, 'remove-canned-responses'))) {
throw new Meteor.Error('error-not-allowed', 'Not allowed');
}
await removeCannedResponse(uid, _id); Try / catch
try {
await removeCannedResponse(uid, _id);
} catch (e) {
if (e instanceof Meteor.Error && e.error === 'error-not-allowed') {
// hide delete actions for this user; do not retry
}
throw e;
} Prevention
- Check 'remove-canned-responses' before rendering delete controls
- Keep canned-response permissions aligned with roles when onboarding agents
- Use privileged service accounts for bulk cleanup scripts
When it happens
Trigger: Calling the removeCannedResponse DDP method with a uid that lacks the 'remove-canned-responses' permission — e.g. livechat agents whose role only has save permissions, or regular users.
Common situations: Role/permission misconfiguration after enabling canned responses; admin UI removing an agent-created response while the acting admin role lost the permission; custom clients reusing a low-privilege token.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
Related errors
- error-not-allowed
- error-canned-response-not-found
- error-action-not-allowed
- error-action-not-allowed
- error-action-not-allowed
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/6d8ad7f8916935ab.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/ee/server/meteor-methods/removeCannedResponse.ts:10
import { CannedResponse } from '@rocket.chat/models';
import { check } from 'meteor/check';
import { Meteor } from 'meteor/meteor';
import { hasPermissionAsync } from '../../../server/lib/authorization/hasPermission';
import notifications from '../../../server/lib/notifications/core/lib/Notifications';
export const removeCannedResponse = async (uid: string, _id: string): Promise<void> => {
if (!(await hasPermissionAsync(uid, 'remove-canned-responses'))) {
throw new Meteor.Error('error-not-allowed', 'Not allowed', {
method: 'removeCannedResponse',
});
}
check(_id, String);
const cannedResponse = await CannedResponse.findOneById(_id);
if (!cannedResponse) {
throw new Meteor.Error('error-canned-response-not-found', 'Canned Response not found', {
method: 'removeCannedResponse',
});
}
notifications.streamCannedResponses.emit('canned-responses', { type: 'removed', _id });
await CannedResponse.removeById(_id);
};
View on GitHub (pinned to b2c16d5842)