RocketChat/Rocket.Chat · error · Error
error-not-allowed
error-not-allowed
Error message
error-not-allowed
What it means
Thrown by GET /api/v1/push.get when the receiver, message, and room all exist but canAccessRoomAsync(room, receiver) is false — the authenticated user is not allowed to read that room. Typical case: requesting push info for a message in a livechat room the user is not part of, a private channel they were removed from, or a DM they are not a party to.
Solutions
- Only open notifications whose push payload targets the current user
- If the user was removed from the room, clear their cached notifications on membership change events
- For service usage, run with an account that legitimately has access (e.g. the room's agent or an admin with the right scope)
Defensive patterns
Strategy: validation
Validate before calling
// verify the current user can see the room before fetching its push info
const { rooms } = await sdk.get('rooms.get');
const canAccess = rooms.some((r) => r._id === rid);
if (!canAccess) throw new Error(`user has no access to room ${rid}`); Try / catch
catch 'error-not-allowed' and hide the notification from the UI (the user lost access — e.g. removed from the channel); never retry the same id for the same user.
Prevention
- Clear cached notifications when membership/subscription removal events arrive
- Bind notifications to the receiving user id and re-check before opening
- Don't forward push payloads between accounts
When it happens
Trigger: GET /api/v1/push.get?id=<messageId> for a message in a room the caller was kicked out of, another user's DM, or a livechat conversation they never served; forwarding message ids between users and fetching notifications cross-user.
Common situations: User removed from a private channel but the mobile client still shows a cached notification; shared queues where one agent taps a notification routed to another agent; ids leaked between sessions in a shared test harness.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
Related errors
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/9d42ef8f81b00f53.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/push.ts:320
const { id } = this.queryParams;
const receiver = await Users.findOneById(this.userId);
if (!receiver) {
throw new Error('error-user-not-found');
}
const message = await Messages.findOneById(id);
if (!message) {
throw new Error('error-message-not-found');
}
const room = await Rooms.findOneById(message.rid);
if (!room) {
throw new Error('error-room-not-found');
}
if (!(await canAccessRoomAsync(room, receiver))) {
throw new Error('error-not-allowed');
}
const data = await PushNotification.getNotificationForMessageId({ receiver, room, message });
return API.v1.success({ data });
},
)
.get(
'push.info',
{
authRequired: true,
response: {
200: pushInfoResponseSchema,
401: validateUnauthorizedErrorResponse,
},
},
async function action() {
const defaultGateway = (await Settings.findOneById('Push_gateway', { projection: { packageValue: 1 } }))?.packageValue;View on GitHub (pinned to b2c16d5842)