{"record":{"id":"3df1cf14e5cd509f","repo":"RocketChat/Rocket.Chat","slug":"error-endpoint-disabled","errorCode":"error-endpoint-disabled","errorMessage":"This endpoint is disabled","messagePattern":"This endpoint is disabled","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/im.ts","lineNumber":798,"sourceCode":"\trequired: ['ims', 'offset', 'count', 'total', 'success'],\n\tadditionalProperties: false,\n});\n\nconst dmMessagesOthersEndpointsProps = {\n\tauthRequired: true as const,\n\tpermissionsRequired: ['view-room-administration'],\n\tresponse: {\n\t\t200: paginatedMessagesResponseSchema,\n\t\t400: validateBadRequestErrorResponse,\n\t\t401: validateUnauthorizedErrorResponse,\n\t\t403: validateForbiddenErrorResponse,\n\t},\n};\n\nconst dmMessagesOthersAction = <Path extends string>(_name: Path): TypedAction<typeof dmMessagesOthersEndpointsProps, Path> =>\n\tasync function action() {\n\t\tif (settings.get('API_Enable_Direct_Message_History_EndPoint') !== true) {\n\t\t\tthrow new Meteor.Error('error-endpoint-disabled', 'This endpoint is disabled', {\n\t\t\t\troute: '/api/v1/im.messages.others',\n\t\t\t});\n\t\t}\n\n\t\tconst { roomId } = this.queryParams;\n\t\tif (!roomId) {\n\t\t\tthrow new Meteor.Error('error-roomid-param-not-provided', 'The parameter \"roomId\" is required');\n\t\t}\n\n\t\tconst room = await Rooms.findOneById<Pick<IRoom, '_id' | 't'>>(roomId, { projection: { _id: 1, t: 1 } });\n\t\tif (!room || room?.t !== 'd') {\n\t\t\tthrow new Meteor.Error('error-room-not-found', `No direct message room found by the id of: ${roomId}`);\n\t\t}\n\n\t\tconst { offset, count } = await getPaginationItems(this.queryParams);\n\t\tconst { sort, fields, query } = await this.parseJsonQuery();\n\t\tconst ourQuery = Object.assign({}, query, { rid: room._id });\n","sourceCodeStart":780,"sourceCodeEnd":816,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/e4b8178b205510181a96ceefee043d0abcd13e5a/apps/meteor/server/api/v1/im.ts#L780-L816","documentation":"Thrown by GET /api/v1/im.messages.others, an admin endpoint that reads other users' direct-message history. The guard at apps/meteor/server/api/v1/im.ts:791 rejects every call unless the workspace setting API_Enable_Direct_Message_History_EndPoint is strictly true; the setting defaults to false (apps/meteor/server/settings/general.ts:9). The check runs before any parameter validation, so even perfectly-formed requests fail while it is off.","triggerScenarios":"Calling GET /api/v1/im.messages.others?roomId=... (with an account holding view-room-administration) on any workspace where API_Enable_Direct_Message_History_EndPoint is false or untouched (default). If the caller lacks the permission you get 403 instead and never reach this throw.","commonSituations":"Fresh installs; compliance-hardened workspaces where the DM-history endpoint was intentionally disabled; scripts developed against a dev server with the flag on and then pointed at production where it is off.","solutions":["Enable the setting: Administration -> General -> REST API -> Enable Direct Message History EndPoint, or POST {\"value\": true} to /api/v1/settings/API_Enable_Direct_Message_History_EndPoint with an admin token","Confirm the caller has view-room-administration, otherwise the next response is 403","If the setting cannot be changed, remove the call - the data is intentionally unavailable on that server"],"exampleFix":"# before\n curl -H \"X-Auth-Token: $TOKEN\" -H \"X-User-Id: $UID\" \\\n  \"https://chat.example.com/api/v1/im.messages.others?roomId=AbCdEf123\"\n # => 400 error-endpoint-disabled\n\n # after: enable it first (admin token), then call\n curl -X POST -H \"X-Auth-Token: $ADMIN_TOKEN\" -H \"X-User-Id: $ADMIN_UID\" \\\n  -H \"Content-Type: application/json\" -d '{\"value\": true}' \\\n  \"https://chat.example.com/api/v1/settings/API_Enable_Direct_Message_History_EndPoint\"\n curl -H \"X-Auth-Token: $TOKEN\" -H \"X-User-Id: $UID\" \\\n  \"https://chat.example.com/api/v1/im.messages.others?roomId=AbCdEf123\"","handlingStrategy":"try-catch","validationCode":"const res = await fetch(`${server}/api/v1/settings/API_Enable_Direct_Message_History_EndPoint`, {\n  headers: { 'X-Auth-Token': adminToken, 'X-User-Id': adminUserId },\n});\nconst { value } = await res.json();\nif (value !== true) {\n  throw new Error('im.messages.others is disabled on this server (API_Enable_Direct_Message_History_EndPoint=false)');\n}","typeGuard":null,"tryCatchPattern":"try {\n  const result = await api.get('/api/v1/im.messages.others', { params: { roomId } });\n} catch (err) {\n  if (err.response?.body?.error === 'error-endpoint-disabled') {\n    // permanent config state - surface to operator, never retry\n    throw new ConfigurationError('DM history endpoint disabled by workspace setting');\n  }\n  throw err;\n}","preventionTips":["Feature-detect optional endpoints before shipping calls to them; treat error-endpoint-disabled as a permanent condition","Keep a per-environment config checklist - dev and prod workspaces rarely share optional API flags","Never auto-retry a 400-class disabled-endpoint response"],"tags":["rest-api","direct-message","settings","disabled-feature","privacy"],"backgroundTag":"endpoint-disabled-by-config","analyzedSha":"e4b8178b205510181a96ceefee043d0abcd13e5a","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}