RocketChat/Rocket.Chat · error · Meteor.Error

error-status-not-allowed

error-status-not-allowed

Error message

Invisible status is disabled

What it means

setUserStatusMethod blocks the 'invisible' status: it computes effectiveStatus = statusType || user.statusDefault || online, and throws when it resolves to UserStatus.OFFLINE while Accounts_AllowInvisibleStatusOption is false. Note the check also fires for users whose saved statusDefault is offline even when they submit without an explicit type.

Solutions

  1. Read Accounts_AllowInvisibleStatusOption from public settings and only offer/submit 'offline' when true
  2. Enable the setting if invisible status should be available
  3. Catch error-status-not-allowed and reset the status picker to a permitted value

Example fix

// before
Meteor.call('setUserStatus', 'offline', statusText);

// after
const allowInvisible = settings.get('Accounts_AllowInvisibleStatusOption');
if (nextStatus !== 'offline' || allowInvisible) {
  Meteor.call('setUserStatus', nextStatus, statusText);
}
Defensive patterns

Strategy: validation

Validate before calling

const allowInvisible = publicSettings['Accounts_AllowInvisibleStatusOption'] === true;
const effective = statusType || user.statusDefault || 'online';
if (effective === 'offline' && !allowInvisible) {
  showNotice('Invisible status is disabled');
  return;
}

Try / catch

catch (err) {
  if (err instanceof Meteor.Error && err.error === 'error-status-not-allowed') {
    resetStatusPickerToValid(); // e.g. 'online'
  }
}

Prevention

When it happens

Trigger: Meteor.call('setUserStatus', 'offline', ...) or saveUserProfile with statusType: 'offline' when Accounts_AllowInvisibleStatusOption is disabled; also a user with statusDefault='offline' sending any update without an explicit statusType.

Common situations: Admins hiding invisible mode by policy; clients with a stale public-settings cache still offering the option; statusDefault persisted from a period when the option was allowed.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/d0701e6ebf7107d2. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/meteor-methods/users/setUserStatus.ts:30

		setUserStatus(statusType: IUser['status'], statusText: IUser['statusText']): void;
	}
}

export const setUserStatusMethod = async (
	user: Pick<IUser, '_id' | 'username' | 'name' | 'status' | 'statusDefault' | 'roles' | 'statusText'>,
	statusType: IUser['status'],
	statusText: IUser['statusText'],
): Promise<void> => {
	if (statusText != null && !settings.get('Accounts_AllowUserStatusMessageChange')) {
		throw new Meteor.Error('error-not-allowed', 'Not allowed', {
			method: 'setUserStatus',
		});
	}

	const effectiveStatus = statusType || user.statusDefault || UserStatus.ONLINE;

	if (effectiveStatus === UserStatus.OFFLINE && !settings.get('Accounts_AllowInvisibleStatusOption')) {
		throw new Meteor.Error('error-status-not-allowed', 'Invisible status is disabled', {
			method: 'setUserStatus',
		});
	}

	await Presence.setStatus(user._id, effectiveStatus, statusText);
};

Meteor.methods<ServerMethods>({
	setUserStatus: async (statusType, statusText) => {
		const user = (await Meteor.userAsync()) as IUser;
		if (!user) {
			throw new Meteor.Error('error-invalid-user', 'Invalid user', { method: 'setUserStatus' });
		}

		await setUserStatusMethod(user, statusType, statusText);
	},
});

View on GitHub (pinned to b2c16d5842)