RocketChat/Rocket.Chat · error · Meteor.Error
error-not-allowed
error-not-allowed
Error message
Not allowed
What it means
addOAuthApp requires the calling user to hold the manage-oauth-apps permission; without it the operation is rejected before any validation happens. The REST layer already enforces permissionsRequired: ['manage-oauth-apps'] (HTTP 403), so this Meteor.Error surfaces from direct method/internal calls - but both paths mean the same thing: the caller's role cannot manage OAuth apps.
Solutions
- Grant manage-oauth-apps to the caller's role in Admin -> Permissions (OAuth Apps section) or promote the user to admin
- Perform the operation logged in as a user who already holds the permission
- Check the role assignment with hasPermissionAsync(uid, 'manage-oauth-apps') before retrying
Example fix
// before: request with a regular user's token POST /api/v1/oauth-apps.create -> 403 / error-not-allowed // after: same request with a token of a user whose role has manage-oauth-apps
Defensive patterns
Strategy: validation
Validate before calling
// check permission before performing the operation
import { hasPermissionAsync } from '../../lib/authorization/hasPermission';
if (!(await hasPermissionAsync(uid, 'manage-oauth-apps'))) {
throw new Meteor.Error('error-not-allowed', 'You need the manage-oauth-apps permission');
}
const app = await addOAuthApp(params, uid); Try / catch
try {
await addOAuthApp(params, uid);
} catch (error) {
if (error instanceof Meteor.Error && error.error === 'error-not-allowed') {
showError('You do not have permission to manage OAuth apps. Ask an admin.');
} else {
throw error;
}
} Prevention
- Grant manage-oauth-apps only to roles that genuinely manage integrations
- Check hasPermissionAsync(uid, 'manage-oauth-apps') in custom UIs before showing the create form
- Audit role permissions after permission reorganizations
When it happens
Trigger: A non-admin user invokes the oauth-apps.create REST endpoint (403 from the route) or the method/function directly without the permission; a role had the permission revoked between UI load and submit.
Common situations: Custom admin dashboards calling the endpoint with a regular user's token; permission cleanup that accidentally removed manage-oauth-apps from an ops role; newly created roles never granted OAuth app rights.
Understand the failure class
Background: "You do not have permission" / 403 Forbidden errors: authenticated but not allowed — causes and fixes across open-source libraries — this error's family across 31 libraries.
Related errors
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/b3ff32863f3e03fd.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/lib/auth/oauth2-server/addOAuthApp.ts:23
import { parseUriList } from './parseUriList';
import type { OauthAppsAddParams } from '../../../api/v1/oauthapps';
import { hasPermissionAsync } from '../../authorization/hasPermission';
export async function addOAuthApp(applicationParams: OauthAppsAddParams, uid: IUser['_id'] | undefined): Promise<IOAuthApps> {
if (!uid) {
throw new Meteor.Error('error-invalid-user', 'Invalid user', { method: 'addOAuthApp' });
}
const user = await Users.findOneById(uid, { projection: { username: 1 } });
if (!user?.username) {
// TODO: username is required, but not always present
throw new Meteor.Error('error-invalid-user', 'Invalid user', { method: 'addOAuthApp' });
}
if (!(await hasPermissionAsync(uid, 'manage-oauth-apps'))) {
throw new Meteor.Error('error-not-allowed', 'Not allowed', { method: 'addOAuthApp' });
}
if (!applicationParams.name || typeof applicationParams.name.valueOf() !== 'string' || applicationParams.name.trim() === '') {
throw new Meteor.Error('error-invalid-name', 'Invalid name', { method: 'addOAuthApp' });
}
if (
!applicationParams.redirectUri ||
typeof applicationParams.redirectUri.valueOf() !== 'string' ||
applicationParams.redirectUri.trim() === ''
) {
throw new Meteor.Error('error-invalid-redirectUri', 'Invalid redirectUri', {
method: 'addOAuthApp',
});
}
if (typeof applicationParams.active !== 'boolean') {
throw new Meteor.Error('error-invalid-arguments', 'Invalid arguments', {View on GitHub (pinned to b2c16d5842)