RocketChat/Rocket.Chat · error · Meteor.Error
error-not-allowed
error-not-allowed
Error message
WebDAV Integration Not Allowed
What it means
The token-based WebDAV account helper throws error-not-allowed ('WebDAV Integration Not Allowed') when the Webdav_Integration_Enabled setting is false. The check runs right after the userId check, before any validation of the token data, so the whole OAuth-based WebDAV flow is gated on the workspace-level toggle.
Solutions
- Enable WebDAV Integration under Admin → WebDAV Integration (Webdav_Integration_Enabled = true)
- Gate the WebDAV UI on the setting so users cannot reach the flow while it is off
- If a script drives account creation, read the setting first and skip gracefully when disabled
Example fix
// before
await call('addWebdavAccountByToken', data); // throws error-not-allowed
// after — verify the workspace toggle first
const res = await fetch('/api/v1/settings/Webdav_Integration_Enabled', { headers });
const { value } = await res.json();
if (value !== true) throw new Error('Enable WebDAV Integration first');
await call('addWebdavAccountByToken', data); Defensive patterns
Strategy: validation
Validate before calling
const res = await fetch('/api/v1/settings/Webdav_Integration_Enabled', { headers: adminHeaders });
const { value } = await res.json();
if (value !== true) throw new Error('Enable WebDAV Integration first');
await call('addWebdavAccountByToken', data); Try / catch
try {
await Meteor.callAsync('addWebdavAccountByToken', data);
} catch (e) {
if (e.error === 'error-not-allowed') {
// WebDAV integration is off: hide the flow and notify the admin
}
} Prevention
- Gate the entire WebDAV UI on Webdav_Integration_Enabled
- Scripts should read the setting before attempting account creation
- Treat error-not-allowed in this flow as a configuration issue, not a bug
When it happens
Trigger: Calling addWebdavAccountByToken (helper or DDP method) while Webdav_Integration_Enabled is false or unset — e.g. the admin never turned on WebDAV Integration, or it was disabled after accounts were set up.
Common situations: Fresh installs where WebDAV was never enabled; users finding the WebDAV UI before the admin flips the setting; the setting being reset during a migration or configuration restore.
Related errors
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/bcd1cd31c9eae853.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts:25
import { settings } from '../../../settings';
import { WebdavClientAdapter } from '../lib/webdavClientAdapter';
declare module '@rocket.chat/ddp-client' {
// eslint-disable-next-line @typescript-eslint/naming-convention
interface ServerMethods {
addWebdavAccount(formData: IWebdavAccountPayload): boolean;
addWebdavAccountByToken(data: IWebdavAccountPayload): boolean;
}
}
export const addWebdavAccountByToken = async (userId: string, data: IWebdavAccountPayload): Promise<boolean> => {
if (!userId) {
throw new Meteor.Error('error-invalid-user', 'Invalid User', { method: 'addWebdavAccount' });
}
if (!settings.get('Webdav_Integration_Enabled')) {
throw new Meteor.Error('error-not-allowed', 'WebDAV Integration Not Allowed', {
method: 'addWebdavAccount',
});
}
check(
data,
Match.ObjectIncluding({
serverURL: String,
token: Match.ObjectIncluding({
access_token: String,
token_type: String,
refresh_token: Match.Optional(String),
}),
name: Match.Maybe(String),
}),
);
try {View on GitHub (pinned to b2c16d5842)