RocketChat/Rocket.Chat · error · Meteor.Error
error-not-allowed
error-not-allowed
Error message
Not Allowed
What it means
Meteor error error-not-allowed thrown by GET channels.online when the authenticated user cannot access the resolved channel (canAccessRoomAsync returns false for this.user). The channel exists and matches the query, but the caller has no membership/visibility rights to see who is online in it — public channels require nothing special, but the room found may be one the user cannot read.
Solutions
- Have the calling user join the channel (channels.join) or get added, then retry
- Verify access first with GET channels.info using the same credentials — it applies the same room-access rules
- For bots, grant a role with the appropriate room visibility or use an admin-scoped token for read-only telemetry
Defensive patterns
Strategy: validation
Validate before calling
try {
await GET('/api/v1/channels.info', { roomId }); // same access rules
} catch {
throw new Error('No access to channel; join it before querying online users');
} Try / catch
try { await GET('/api/v1/channels.online', { _id: roomId }); } catch (e) {
if (e.error === 'error-not-allowed') { /* prompt join or use privileged token */ }
} Prevention
- Grant bot tokens membership in the channels they monitor
- Use narrow queries so channels.online resolves to the intended room
When it happens
Trigger: GET /api/v1/channels.online?_id=<channelId> (or with a query) where the user is not a member of a channel whose access rules exclude them (e.g. broadcast/teamsRoom restrictions, or the room matched by a loose query is not actually accessible).
Common situations: Bot tokens querying channels they were never invited to; query filter matching an unexpected room (missing t:'c' nuance aside, a broad query can resolve to a room the bot cannot see); user was kicked between list load and the online fetch.
Understand the failure class
Background: "You do not have permission" / 403 Forbidden errors: authenticated but not allowed — causes and fixes across open-source libraries — this error's family across 31 libraries.
Related errors
- unauthorized
- error-invalid-role
- error-permission-not-found
- error-action-not-allowed
- error-action-not-allowed
AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-09-08).
Data as JSON: /api/errors/bd1aa371aece302f.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/channels.ts:1735
const { _id } = this.queryParams;
if ((!query || Object.keys(query).length === 0) && !_id) {
return API.v1.failure('Invalid query');
}
const filter = {
...query,
...(_id ? { _id } : {}),
t: 'c',
};
const room = await Rooms.findOne(filter as Record<string, any>);
if (!room) {
return API.v1.failure('Channel does not exists');
}
if (!(await canAccessRoomAsync(room, this.user))) {
throw new Meteor.Error('error-not-allowed', 'Not Allowed');
}
const hidden = await getUsersHiddenFrom(this.userId);
const online: Pick<IUser, '_id' | 'username'>[] = filterHiddenUsers(
await Users.findUsersNotOffline({
projection: { username: 1 },
}).toArray(),
hidden,
);
const onlineInRoom = await Promise.all(
online.map(async (user) => {
const subscription = await Subscriptions.findOneByRoomIdAndUserId(room._id, user._id, {
projection: { _id: 1, username: 1 },
});
if (subscription) {
return {View on GitHub (pinned to e4b8178b20)