RocketChat/Rocket.Chat · error · Meteor.Error
Not allowed
Not allowed
Error message
Not allowed
What it means
Meteor.Error 'Not allowed' thrown by requireAuditor when the audit-message method is invoked with a null/absent userId — i.e. there is no authenticated user on the DDP method context at all. The audit API (auditGetMessagesMethod) refuses to run anonymously before any permission lookup happens.
Solutions
- Ensure the method call runs on an authenticated connection (valid login token / this.userId set)
- For server-side code, pass an explicit userId or use an authenticated REST endpoint instead of a raw method call
- Handle 401-style 'Not allowed' by re-authenticating rather than retrying blindly
Example fix
// before: invoking the audit method without a user context
Meteor.call('auditMessages', params);
// after: run it as an authenticated user (client) or bound server-side
// client: ensure Meteor.userId() is set before calling
if (!Meteor.userId()) {
throw new Error('Login required for auditing');
}
Meteor.call('auditMessages', params);
// server: Meteor.call with a bound user or use promise with authenticated userId Defensive patterns
Strategy: try-catch
Validate before calling
// On the client, ensure an authenticated session before invoking audit methods
if (!Meteor.userId()) {
throw new Error('Authentication required');
} Try / catch
try {
const results = await auditGetMessagesMethod(this.userId, params);
} catch (err: any) {
if (err?.error === 'Not allowed' && !userId) {
// re-authenticate; retrying with the same null userId will always fail
}
throw err;
} Prevention
- Bind DDP method calls to authenticated connections with valid login tokens
- Check Meteor.userId() before calling protected methods
- Prefer authenticated REST endpoints for integration access to audit data
When it happens
Trigger: Calling the auditMessages meteor method from an unauthenticated connection; a method binding losing the user context (e.g. server-side invocation without this.userId); token expiry dropping the user between connect and method call.
Common situations: Scripts calling internal methods without login tokens; custom integrations using DDP without auth; session invalidated server-side mid-flight.
Related errors
- Room doesn't exist
- 403
- Adding SAML service is deprecated
- App could not be enabled
- App metadata download failed
AI-assisted analysis of RocketChat/Rocket.Chat@2a7de45707 (2026-08-18).
Data as JSON: /api/errors/259c7bef31f4cd06.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/ee/server/lib/audit/functions.ts:59
}
if (type === 'l') {
const extraQuery = await callbacks.run('livechat.applyRoomRestrictions', {}, { userId });
const rooms = await LivechatRooms.findByVisitorIdAndAgentId(
visitor,
agent,
{
projection: { _id: 1 },
},
extraQuery,
).toArray();
return rooms?.length ? { rids: rooms.map(({ _id }) => _id), name: i18n.t('Omnichannel') } : undefined;
}
};
const requireAuditor = async (userId: string | null): Promise<IUser> => {
if (!userId) {
throw new Meteor.Error('Not allowed');
}
const user = await Users.findOneById(userId);
if (!user || !(await hasPermissionAsync(user._id, 'can-audit'))) {
throw new Meteor.Error('Not allowed');
}
return user;
};
type AuditMessagesParams = {
rid?: IRoom['_id'];
startDate: Date;
endDate: Date;
users: NonNullable<IUser['username']>[];
msg: IMessage['msg'];
type: string;
visitor?: ILivechatVisitor['_id'];
agent?: ILivechatAgent['_id'];View on GitHub (pinned to 2a7de45707)