RocketChat/Rocket.Chat · error · Meteor.Error

error-not-allowed

error-not-allowed

Error message

WebDAV Integration Not Allowed

What it means

The token-based WebDAV account helper throws error-not-allowed ('WebDAV Integration Not Allowed') when the Webdav_Integration_Enabled setting is false. The check runs right after the userId check, before any validation of the token data, so the whole OAuth-based WebDAV flow is gated on the workspace-level toggle.

Solutions

  1. Enable WebDAV Integration under Admin → WebDAV Integration (Webdav_Integration_Enabled = true)
  2. Gate the WebDAV UI on the setting so users cannot reach the flow while it is off
  3. If a script drives account creation, read the setting first and skip gracefully when disabled

Example fix

// before
await call('addWebdavAccountByToken', data); // throws error-not-allowed

// after — verify the workspace toggle first
const res = await fetch('/api/v1/settings/Webdav_Integration_Enabled', { headers });
const { value } = await res.json();
if (value !== true) throw new Error('Enable WebDAV Integration first');
await call('addWebdavAccountByToken', data);
Defensive patterns

Strategy: validation

Validate before calling

const res = await fetch('/api/v1/settings/Webdav_Integration_Enabled', { headers: adminHeaders });
const { value } = await res.json();
if (value !== true) throw new Error('Enable WebDAV Integration first');
await call('addWebdavAccountByToken', data);

Try / catch

try {
  await Meteor.callAsync('addWebdavAccountByToken', data);
} catch (e) {
  if (e.error === 'error-not-allowed') {
    // WebDAV integration is off: hide the flow and notify the admin
  }
}

Prevention

When it happens

Trigger: Calling addWebdavAccountByToken (helper or DDP method) while Webdav_Integration_Enabled is false or unset — e.g. the admin never turned on WebDAV Integration, or it was disabled after accounts were set up.

Common situations: Fresh installs where WebDAV was never enabled; users finding the WebDAV UI before the admin flips the setting; the setting being reset during a migration or configuration restore.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/bcd1cd31c9eae853. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts:25

import { settings } from '../../../settings';
import { WebdavClientAdapter } from '../lib/webdavClientAdapter';

declare module '@rocket.chat/ddp-client' {
	// eslint-disable-next-line @typescript-eslint/naming-convention
	interface ServerMethods {
		addWebdavAccount(formData: IWebdavAccountPayload): boolean;
		addWebdavAccountByToken(data: IWebdavAccountPayload): boolean;
	}
}

export const addWebdavAccountByToken = async (userId: string, data: IWebdavAccountPayload): Promise<boolean> => {
	if (!userId) {
		throw new Meteor.Error('error-invalid-user', 'Invalid User', { method: 'addWebdavAccount' });
	}

	if (!settings.get('Webdav_Integration_Enabled')) {
		throw new Meteor.Error('error-not-allowed', 'WebDAV Integration Not Allowed', {
			method: 'addWebdavAccount',
		});
	}

	check(
		data,
		Match.ObjectIncluding({
			serverURL: String,
			token: Match.ObjectIncluding({
				access_token: String,
				token_type: String,
				refresh_token: Match.Optional(String),
			}),
			name: Match.Maybe(String),
		}),
	);

	try {

View on GitHub (pinned to b2c16d5842)