RocketChat/Rocket.Chat · error · Meteor.Error

error-not-allowed

error-not-allowed

Error message

Change avatar is not allowed

What it means

Thrown by POST users.setAvatar when the workspace setting Accounts_AllowUserAvatarChange is false AND the caller lacks the edit-other-user-avatar permission. The check is a workspace-wide feature gate: avatar changes are disabled for regular users, and only that permission overrides the gate.

Solutions

  1. Enable the setting: Administration > Accounts > Allow User Avatar Change (or PATCH settings/Accounts_AllowUserAvatarChange to true)
  2. Otherwise perform avatar changes from an account holding edit-other-user-avatar
  3. Feature-detect in the UI (fetch that setting or hide the control when unavailable) so users never hit the raw error

Example fix

// before
ui.showAvatarUpload = true; // always
// after
const { value } = await sdk.get('settings', { query: { query: JSON.stringify({ _id: 'Accounts_AllowUserAvatarChange' }) } });
ui.showAvatarUpload = canEditOthers || value === true;
Defensive patterns

Strategy: validation

Validate before calling

const enabled = await settingValue('Accounts_AllowUserAvatarChange');
if (!enabled && !(await hasPermission('edit-other-user-avatar'))) throw new Error('avatar change disabled on this workspace');
await sdk.post('users.setAvatar', payload);

Try / catch

catch (e) { if (e?.error === 'error-not-allowed' && e?.details?.method === 'users.setAvatar') hideAvatarUpload(); else throw e; }

Prevention

When it happens

Trigger: POST users.setAvatar (self or other) on a workspace where an admin disabled Accounts_AllowUserAvatarChange, by a caller without edit-other-user-avatar; common in locked-down corporate deployments; admins testing with a non-admin token after flipping the setting.

Common situations: Branding policies that forbid custom avatars; compliance workspaces centralizing avatars via LDAP/AD sync; clients not feature-detecting and showing a broken avatar upload UI.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-08-18). Data as JSON: /api/errors/b50760eeefdfd47e. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/users.ts:303

		},
	)
	.post(
		'users.setAvatar',
		{
			authRequired: true,
			body: isUsersSetAvatarProps,
			response: {
				200: voidSuccessResponse,
				400: validateBadRequestErrorResponse,
				401: validateUnauthorizedErrorResponse,
				403: validateForbiddenErrorResponse,
			},
		},
		async function action() {
			const canEditOtherUserAvatar = await hasPermissionAsync(this.user, 'edit-other-user-avatar');

			if (!settings.get('Accounts_AllowUserAvatarChange') && !canEditOtherUserAvatar) {
				throw new Meteor.Error('error-not-allowed', 'Change avatar is not allowed', {
					method: 'users.setAvatar',
				});
			}

			let user = await (async (): Promise<Pick<IUser, '_id' | 'username'> | undefined | null> => {
				if (isUserFromParams(this.bodyParams, this.userId, this.user)) {
					return Users.findOneById(this.userId);
				}
				if (canEditOtherUserAvatar) {
					return getUserFromParams(this.bodyParams);
				}
			})();

			if (!user) {
				return API.v1.forbidden();
			}

			if (this.bodyParams.avatarUrl) {

View on GitHub (pinned to e4b8178b20)