{"record":{"id":"1932a62194f829a7","repo":"RocketChat/Rocket.Chat","slug":"error-action-not-allowed-1932a6","errorCode":"error-action-not-allowed","errorMessage":"Notify ${mention} in this room not allowed","messagePattern":"Notify (.+?) in this room not allowed","errorType":"error_code","errorClass":"MeteorError","httpStatus":null,"severity":"error","filePath":"apps/meteor/server/services/messages/hooks/BeforeSavePreventMention.ts","lineNumber":34,"sourceCode":"\t\tpermission: string;\n\t}): Promise<boolean> {\n\t\tif (!message.mentions?.some(({ _id }) => _id === mention)) {\n\t\t\treturn true;\n\t\t}\n\n\t\t// Check if the user has permissions to use @all in both global and room scopes.\n\t\tif (await Authorization.hasPermission(message.u._id, permission)) {\n\t\t\treturn true;\n\t\t}\n\n\t\tif (await Authorization.hasPermission(message.u._id, permission, message.rid)) {\n\t\t\treturn true;\n\t\t}\n\n\t\tconst action = i18n.t('Notify_all_in_this_room', { lng: user.language });\n\n\t\t// Also throw to stop propagation of 'sendMessage'.\n\t\tthrow new MeteorError('error-action-not-allowed', `Notify ${mention} in this room not allowed`, {\n\t\t\taction,\n\t\t});\n\t}\n}\n","sourceCodeStart":16,"sourceCodeEnd":39,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/services/messages/hooks/BeforeSavePreventMention.ts#L16-L39","documentation":"BeforeSavePreventMention checks the sender's permission for the given mention permission (e.g. mention-all / mention-here) in both global scope and room scope via Authorization.hasPermission. If neither grants it, the hook throws Meteor error-action-not-allowed with the hardcoded message 'Notify ${mention} in this room not allowed' (a localized action text is attached in the error details), stopping sendMessage.","triggerScenarios":"A user lacking the mention permission globally AND for that specific room sends a message containing @all/@here; the pre-save hook rejects it before persistence.","commonSituations":"Default roles without mention-all in large workspaces; bots/integrations posting as users who lack the permission; guests attempting @here.","solutions":["Grant the role the relevant mention permission globally or on that room (Administration → Permissions)","Remove the mention from the message text","Route announcements through a user/role that holds the permission, or use a dedicated announcement mechanism"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"import { Authorization } from '@rocket.chat/core-services';\n\nconst canMention =\n  (await Authorization.hasPermission(uid, 'mention-all')) ||\n  (await Authorization.hasPermission(uid, 'mention-all', rid));\nif (!canMention) {\n  msg = msg.replace(/@all|@here/g, '').trim(); // avoid the guaranteed rejection\n}","typeGuard":null,"tryCatchPattern":"try {\n  await sendMessage(userId, { rid, msg });\n} catch (err) {\n  if (err?.error === 'error-action-not-allowed' && /Notify/.test(err?.message ?? '')) {\n    // permission problem: tell the sender they lack the mention permission; do not retry as-is\n    return notifyMissingPermission(userId, 'mention-all');\n  }\n  throw err;\n}","preventionTips":["Check mention permissions (global and room-scoped) before sending @all/@here","Hide/disable mention-all UI for roles without the permission","Route broadcasts through accounts that hold the permission"],"tags":["mentions","permissions","authorization","rocket-chat"],"backgroundTag":"missing-permission","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}