RocketChat/Rocket.Chat · error · Meteor.Error
error-not-allowed
error-not-allowed
Error message
Change avatar is not allowed
What it means
Thrown by POST users.setAvatar when the workspace setting Accounts_AllowUserAvatarChange is false AND the caller lacks the edit-other-user-avatar permission. The check is a workspace-wide feature gate: avatar changes are disabled for regular users, and only that permission overrides the gate.
Solutions
- Enable the setting: Administration > Accounts > Allow User Avatar Change (or PATCH settings/Accounts_AllowUserAvatarChange to true)
- Otherwise perform avatar changes from an account holding edit-other-user-avatar
- Feature-detect in the UI (fetch that setting or hide the control when unavailable) so users never hit the raw error
Example fix
// before
ui.showAvatarUpload = true; // always
// after
const { value } = await sdk.get('settings', { query: { query: JSON.stringify({ _id: 'Accounts_AllowUserAvatarChange' }) } });
ui.showAvatarUpload = canEditOthers || value === true; Defensive patterns
Strategy: validation
Validate before calling
const enabled = await settingValue('Accounts_AllowUserAvatarChange');
if (!enabled && !(await hasPermission('edit-other-user-avatar'))) throw new Error('avatar change disabled on this workspace');
await sdk.post('users.setAvatar', payload); Try / catch
catch (e) { if (e?.error === 'error-not-allowed' && e?.details?.method === 'users.setAvatar') hideAvatarUpload(); else throw e; } Prevention
- Feature-detect Accounts_AllowUserAvatarChange before showing upload UI
- On locked-down workspaces use an account with edit-other-user-avatar for managed avatars
When it happens
Trigger: POST users.setAvatar (self or other) on a workspace where an admin disabled Accounts_AllowUserAvatarChange, by a caller without edit-other-user-avatar; common in locked-down corporate deployments; admins testing with a non-admin token after flipping the setting.
Common situations: Branding policies that forbid custom avatars; compliance workspaces centralizing avatars via LDAP/AD sync; clients not feature-detecting and showing a broken avatar upload UI.
Related errors
AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-08-18).
Data as JSON: /api/errors/b50760eeefdfd47e.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/users.ts:303
},
)
.post(
'users.setAvatar',
{
authRequired: true,
body: isUsersSetAvatarProps,
response: {
200: voidSuccessResponse,
400: validateBadRequestErrorResponse,
401: validateUnauthorizedErrorResponse,
403: validateForbiddenErrorResponse,
},
},
async function action() {
const canEditOtherUserAvatar = await hasPermissionAsync(this.user, 'edit-other-user-avatar');
if (!settings.get('Accounts_AllowUserAvatarChange') && !canEditOtherUserAvatar) {
throw new Meteor.Error('error-not-allowed', 'Change avatar is not allowed', {
method: 'users.setAvatar',
});
}
let user = await (async (): Promise<Pick<IUser, '_id' | 'username'> | undefined | null> => {
if (isUserFromParams(this.bodyParams, this.userId, this.user)) {
return Users.findOneById(this.userId);
}
if (canEditOtherUserAvatar) {
return getUserFromParams(this.bodyParams);
}
})();
if (!user) {
return API.v1.forbidden();
}
if (this.bodyParams.avatarUrl) {View on GitHub (pinned to e4b8178b20)