RocketChat/Rocket.Chat · error · Error

error-not-allowed

Error message

error-not-allowed

What it means

Thrown by GET /api/v1/livechat/room.join when canAccessRoomAsync(room, user) resolves false. The room exists, is open, and MAC limits allow the join, but this particular authenticated user is not permitted to access this omnichannel room (despite holding the route-level view-l-room permission).

Solutions

  1. Give the user access: add them to the room's unit/department or assign the appropriate livechat roles/permissions
  2. Verify with an admin what canAccessRoom evaluates for that user/room pair (units, departments, roles)
  3. If broad monitoring is intended, grant the permission set that omnichannel monitors use (e.g. view-livechat-rooms / monitor arrangements) instead of relying on join
Defensive patterns

Strategy: try-catch

Try / catch

try { await joinRoom(roomId); } catch (e) { if (e.message === 'error-not-allowed') { showNeedsAccessMessage(roomId); return; } throw e; }

Prevention

When it happens

Trigger: An agent outside the room's unit/department restrictions joining a conversation scoped to another unit; users without the livechat-agent role or without membership trying to join; deployments using livechat delegation/units that scope room visibility.

Common situations: Multi-unit installs where agents see only their unit's conversations; agents attempting to join inquiries routed to a department they do not belong to; custom agent desks assuming all agents can join any open room.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/bf9c5997d81c3f4b. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/omnichannel/room.ts:430

				throw new Error('error-invalid-user');
			}

			const room = await LivechatRooms.findOneById(roomId);

			if (!room) {
				throw new Error('error-invalid-room');
			}

			if (!room.open) {
				throw new Error('room-closed');
			}

			if (!(await Omnichannel.isWithinMACLimit(room))) {
				throw new Error('error-mac-limit-reached');
			}

			if (!(await canAccessRoomAsync(room, user))) {
				throw new Error('error-not-allowed');
			}

			await addUserToRoom(roomId, user);

			return API.v1.success();
		},
	},
);

API.v1.addRoute(
	'livechat/room.saveInfo',
	{ authRequired: true, permissionsRequired: ['view-l-room'], validateParams: isLiveChatRoomSaveInfoProps },
	{
		async post() {
			const { roomData, guestData } = this.bodyParams;
			const room = await LivechatRooms.findOneById(roomData._id);
			if (!room || !isOmnichannelRoom(room)) {
				throw new Error('error-invalid-room');

View on GitHub (pinned to b2c16d5842)