RocketChat/Rocket.Chat · error · Meteor.Error
error-not-allowed
error-not-allowed
Error message
Not allowed
What it means
Thrown by GET /api/v1/roles.getUsersInRole when a `roomId` query param is supplied and the caller lacks the view-other-user-channels permission. The endpoint itself only demands access-permissions; narrowing results to a room additionally requires being able to see other users' channel memberships — a scoped permission admins often forget to grant.
Solutions
- Grant the caller's role the view-other-user-channels permission (Administration > Permissions)
- If you don't strictly need room scoping, drop the roomId param
- For service accounts, prefer a role that mirrors the full admin permission set rather than hand-picking
Example fix
// before
await sdk.get('roles.getUsersInRole', { role, roomId });
// after (only scope by room when you hold the permission)
await sdk.get('roles.getUsersInRole', hasPermission('view-other-user-channels') ? { role, roomId } : { role }); Defensive patterns
Strategy: validation
Validate before calling
// only scope by room when the session user actually holds the permission
const canSeeOtherChannels = me.permissions?.includes('view-other-user-channels');
await sdk.get('roles.getUsersInRole', canSeeOtherChannels ? { role, roomId } : { role }); Try / catch
catch 'error-not-allowed' and fall back to the unscoped call (drop roomId) if room-scoped results are optional for your use case; otherwise surface a clear 'missing view-other-user-channels' configuration message.
Prevention
- Document which extra permissions each roomId-using endpoint needs
- Keep service-account permission sets in sync with endpoint requirements
- Default to unscoped queries unless room filtering is essential
When it happens
Trigger: GET /api/v1/roles.getUsersInRole?role=<id>&roomId=<rid> as a user with access-permissions but without view-other-user-channels. Omitting roomId returns the role's users across scopes and never triggers this.
Common situations: Custom admin dashboards where the service account has permission management rights but not channel-visibility rights; new workspaces where view-other-user-channels was revoked from the admin's role set; scripts copied between instances with divergent permission sets.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
Related errors
- error-invalid-role
- error-action-not-allowed
- error-action-not-allowed
- error-action-not-allowed
- error-invalid-param
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/edebc7cbc763a918.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/roles.ts:193
},
async function action() {
const { roomId, role } = this.queryParams;
const { offset, count = 50 } = await getPaginationItems(this.queryParams);
const projection = {
name: 1,
username: 1,
emails: 1,
avatarETag: 1,
createdAt: 1,
_updatedAt: 1,
};
if (!role) {
throw new Meteor.Error('error-param-not-provided', 'Query param "role" is required');
}
if (roomId && !(await hasPermissionAsync(this.user, 'view-other-user-channels'))) {
throw new Meteor.Error('error-not-allowed', 'Not allowed');
}
const options = { projection: { _id: 1 } };
const roleData = await Roles.findOneById<Pick<IRole, '_id'>>(role, options);
if (!roleData) {
throw new Meteor.Error('error-invalid-roleId');
}
const { cursor, totalCount } = await getUsersInRolePaginated(roleData._id, roomId, {
limit: count,
sort: { username: 1 },
skip: offset,
projection,
});
const [users, total] = await Promise.all([cursor.toArray(), totalCount]);
View on GitHub (pinned to b2c16d5842)