RocketChat/Rocket.Chat · error · Meteor.Error

error-not-allowed

error-not-allowed

Error message

Not allowed

What it means

Thrown by GET /api/v1/roles.getUsersInRole when a `roomId` query param is supplied and the caller lacks the view-other-user-channels permission. The endpoint itself only demands access-permissions; narrowing results to a room additionally requires being able to see other users' channel memberships — a scoped permission admins often forget to grant.

Solutions

  1. Grant the caller's role the view-other-user-channels permission (Administration > Permissions)
  2. If you don't strictly need room scoping, drop the roomId param
  3. For service accounts, prefer a role that mirrors the full admin permission set rather than hand-picking

Example fix

// before
await sdk.get('roles.getUsersInRole', { role, roomId });

// after (only scope by room when you hold the permission)
await sdk.get('roles.getUsersInRole', hasPermission('view-other-user-channels') ? { role, roomId } : { role });
Defensive patterns

Strategy: validation

Validate before calling

// only scope by room when the session user actually holds the permission
const canSeeOtherChannels = me.permissions?.includes('view-other-user-channels');
await sdk.get('roles.getUsersInRole', canSeeOtherChannels ? { role, roomId } : { role });

Try / catch

catch 'error-not-allowed' and fall back to the unscoped call (drop roomId) if room-scoped results are optional for your use case; otherwise surface a clear 'missing view-other-user-channels' configuration message.

Prevention

When it happens

Trigger: GET /api/v1/roles.getUsersInRole?role=<id>&roomId=<rid> as a user with access-permissions but without view-other-user-channels. Omitting roomId returns the role's users across scopes and never triggers this.

Common situations: Custom admin dashboards where the service account has permission management rights but not channel-visibility rights; new workspaces where view-other-user-channels was revoked from the admin's role set; scripts copied between instances with divergent permission sets.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/edebc7cbc763a918. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/roles.ts:193

		},
		async function action() {
			const { roomId, role } = this.queryParams;
			const { offset, count = 50 } = await getPaginationItems(this.queryParams);

			const projection = {
				name: 1,
				username: 1,
				emails: 1,
				avatarETag: 1,
				createdAt: 1,
				_updatedAt: 1,
			};

			if (!role) {
				throw new Meteor.Error('error-param-not-provided', 'Query param "role" is required');
			}
			if (roomId && !(await hasPermissionAsync(this.user, 'view-other-user-channels'))) {
				throw new Meteor.Error('error-not-allowed', 'Not allowed');
			}

			const options = { projection: { _id: 1 } };
			const roleData = await Roles.findOneById<Pick<IRole, '_id'>>(role, options);

			if (!roleData) {
				throw new Meteor.Error('error-invalid-roleId');
			}

			const { cursor, totalCount } = await getUsersInRolePaginated(roleData._id, roomId, {
				limit: count,
				sort: { username: 1 },
				skip: offset,
				projection,
			});

			const [users, total] = await Promise.all([cursor.toArray(), totalCount]);

View on GitHub (pinned to b2c16d5842)