RocketChat/Rocket.Chat · error
The setting " " is not readable.
Error message
The setting "${id}" is not readable. What it means
getOneById on the settings bridge returns readable settings only. getReadableSettingById returns null when the app is unknown to the manager, the setting id does not exist, the setting is hidden while the app lacks the 'server-setting.read' permission (or that permission does not allowlist the id in hiddenSettings), or the app declares no permissions at all (then only non-hidden settings are readable). All of these surface as 'The setting ... is not readable.'
Solutions
- Confirm the setting id exists on this server version (Administration > Workspace > Settings, or the settings source).
- Declare a permission { name: 'server-setting.read', hiddenSettings: ['<setting-id>'] } in the app manifest and reinstall the app.
- For the app's own configuration, use the app-settings API instead of server settings; secret settings are never readable by apps.
Example fix
// before - manifest has no permissions, app reads a hidden setting
const setting = await this.read.getSettingReader().getById('LDAP_Password'); // throws
// after - app.json declares the permission
// 'permissions': [{ 'name': 'server-setting.read', 'hiddenSettings': ['LDAP_Password'] }]
const setting = await this.read.getSettingReader().getById('LDAP_Password'); Defensive patterns
Strategy: try-catch
Try / catch
Catch the 'is not readable' message, log the setting id, and branch: unknown id -> fix the id; hidden setting -> declare server-setting.read with hiddenSettings; secret -> give up, secrets are never readable.
Prevention
- Declare 'server-setting.read' (with hiddenSettings entries) in the manifest up front if you read server settings.
- Prefer app settings for app configuration.
- Audit setting ids after each Rocket.Chat server upgrade.
When it happens
Trigger: App reads a hidden server setting (e.g. credentials) without declaring 'server-setting.read' with the id in hiddenSettings; app reads a setting id that does not exist on this server version; app code runs under an appId the manager no longer knows (uninstalled mid-flight).
Common situations: Apps trying to read SMTP/LDAP/OAuth secrets; settings renamed or removed between Rocket.Chat versions; permission block missing from the app manifest.
Related errors
- The setting " " is not readable.
- error-action-not-allowed
- error-action-not-allowed
- error-action-not-allowed
- error-action-not-allowed
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/e340638a4079887e.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/app/apps/server/bridges/settings.ts:27
export class AppSettingBridge extends ServerSettingBridge {
constructor(private readonly orch: IAppServerOrchestrator) {
super();
}
protected async getAll(appId: string): Promise<Array<ISetting>> {
this.orch.debugLog(`The App ${appId} is getting all the settings.`);
const settings = await Settings.find({ secret: false }).toArray();
return settings.map((s) => this.orch.getConverters()?.get('settings').convertToApp(s));
}
protected async getOneById(id: string, appId: string): Promise<ISetting> {
this.orch.debugLog(`The App ${appId} is getting the setting by id ${id}.`);
const setting = await this.getReadableSettingById(id, appId);
if (!setting) {
throw new Error(`The setting "${id}" is not readable.`);
}
return setting;
}
protected async hideGroup(name: string, appId: string): Promise<void> {
this.orch.debugLog(`The App ${appId} is hidding the group ${name}.`);
throw new Error('Method not implemented.');
}
protected async hideSetting(id: string, appId: string): Promise<void> {
this.orch.debugLog(`The App ${appId} is hidding the setting ${id}.`);
if (!(await this.isReadableById(id, appId))) {
throw new Error(`The setting "${id}" is not readable.`);
}
View on GitHub (pinned to b2c16d5842)