RocketChat/Rocket.Chat · error · Meteor.Error

Not allowed

Not allowed

Error message

Not allowed

What it means

Meteor.Error 'Not allowed' thrown by requireAuditor when the audit-message method is invoked with a null/absent userId — i.e. there is no authenticated user on the DDP method context at all. The audit API (auditGetMessagesMethod) refuses to run anonymously before any permission lookup happens.

Solutions

  1. Ensure the method call runs on an authenticated connection (valid login token / this.userId set)
  2. For server-side code, pass an explicit userId or use an authenticated REST endpoint instead of a raw method call
  3. Handle 401-style 'Not allowed' by re-authenticating rather than retrying blindly

Example fix

// before: invoking the audit method without a user context
Meteor.call('auditMessages', params);

// after: run it as an authenticated user (client) or bound server-side
// client: ensure Meteor.userId() is set before calling
if (!Meteor.userId()) {
  throw new Error('Login required for auditing');
}
Meteor.call('auditMessages', params);
// server: Meteor.call with a bound user or use promise with authenticated userId
Defensive patterns

Strategy: try-catch

Validate before calling

// On the client, ensure an authenticated session before invoking audit methods
if (!Meteor.userId()) {
  throw new Error('Authentication required');
}

Try / catch

try {
  const results = await auditGetMessagesMethod(this.userId, params);
} catch (err: any) {
  if (err?.error === 'Not allowed' && !userId) {
    // re-authenticate; retrying with the same null userId will always fail
  }
  throw err;
}

Prevention

When it happens

Trigger: Calling the auditMessages meteor method from an unauthenticated connection; a method binding losing the user context (e.g. server-side invocation without this.userId); token expiry dropping the user between connect and method call.

Common situations: Scripts calling internal methods without login tokens; custom integrations using DDP without auth; session invalidated server-side mid-flight.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@2a7de45707 (2026-08-18). Data as JSON: /api/errors/259c7bef31f4cd06. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/ee/server/lib/audit/functions.ts:59

	}

	if (type === 'l') {
		const extraQuery = await callbacks.run('livechat.applyRoomRestrictions', {}, { userId });
		const rooms = await LivechatRooms.findByVisitorIdAndAgentId(
			visitor,
			agent,
			{
				projection: { _id: 1 },
			},
			extraQuery,
		).toArray();
		return rooms?.length ? { rids: rooms.map(({ _id }) => _id), name: i18n.t('Omnichannel') } : undefined;
	}
};

const requireAuditor = async (userId: string | null): Promise<IUser> => {
	if (!userId) {
		throw new Meteor.Error('Not allowed');
	}

	const user = await Users.findOneById(userId);
	if (!user || !(await hasPermissionAsync(user._id, 'can-audit'))) {
		throw new Meteor.Error('Not allowed');
	}
	return user;
};

type AuditMessagesParams = {
	rid?: IRoom['_id'];
	startDate: Date;
	endDate: Date;
	users: NonNullable<IUser['username']>[];
	msg: IMessage['msg'];
	type: string;
	visitor?: ILivechatVisitor['_id'];
	agent?: ILivechatAgent['_id'];

View on GitHub (pinned to 2a7de45707)