RocketChat/Rocket.Chat · error · Error

error-not-allowed

error-not-allowed

Error message

error-not-allowed

What it means

Thrown by GET /api/v1/push.get when the receiver, message, and room all exist but canAccessRoomAsync(room, receiver) is false — the authenticated user is not allowed to read that room. Typical case: requesting push info for a message in a livechat room the user is not part of, a private channel they were removed from, or a DM they are not a party to.

Solutions

  1. Only open notifications whose push payload targets the current user
  2. If the user was removed from the room, clear their cached notifications on membership change events
  3. For service usage, run with an account that legitimately has access (e.g. the room's agent or an admin with the right scope)
Defensive patterns

Strategy: validation

Validate before calling

// verify the current user can see the room before fetching its push info
const { rooms } = await sdk.get('rooms.get');
const canAccess = rooms.some((r) => r._id === rid);
if (!canAccess) throw new Error(`user has no access to room ${rid}`);

Try / catch

catch 'error-not-allowed' and hide the notification from the UI (the user lost access — e.g. removed from the channel); never retry the same id for the same user.

Prevention

When it happens

Trigger: GET /api/v1/push.get?id=<messageId> for a message in a room the caller was kicked out of, another user's DM, or a livechat conversation they never served; forwarding message ids between users and fetching notifications cross-user.

Common situations: User removed from a private channel but the mobile client still shows a cached notification; shared queues where one agent taps a notification routed to another agent; ids leaked between sessions in a shared test harness.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/9d42ef8f81b00f53. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/push.ts:320

			const { id } = this.queryParams;

			const receiver = await Users.findOneById(this.userId);
			if (!receiver) {
				throw new Error('error-user-not-found');
			}

			const message = await Messages.findOneById(id);
			if (!message) {
				throw new Error('error-message-not-found');
			}

			const room = await Rooms.findOneById(message.rid);
			if (!room) {
				throw new Error('error-room-not-found');
			}

			if (!(await canAccessRoomAsync(room, receiver))) {
				throw new Error('error-not-allowed');
			}

			const data = await PushNotification.getNotificationForMessageId({ receiver, room, message });

			return API.v1.success({ data });
		},
	)
	.get(
		'push.info',
		{
			authRequired: true,
			response: {
				200: pushInfoResponseSchema,
				401: validateUnauthorizedErrorResponse,
			},
		},
		async function action() {
			const defaultGateway = (await Settings.findOneById('Push_gateway', { projection: { packageValue: 1 } }))?.packageValue;

View on GitHub (pinned to b2c16d5842)