{"record":{"id":"6657c7446c97957c","repo":"RocketChat/Rocket.Chat","slug":"error-action-not-allowed-6657c7","errorCode":"error-action-not-allowed","errorMessage":"This is an enterprise feature","messagePattern":"This is an enterprise feature","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/ee/server/api/roles.ts","lineNumber":115,"sourceCode":"\trequired: ['role', 'success'],\n\tadditionalProperties: false,\n});\n\nAPI.v1.post(\n\t'roles.create',\n\t{\n\t\tauthRequired: true,\n\t\tlicense: ['custom-roles'],\n\t\tbody: isRoleCreateProps,\n\t\tresponse: {\n\t\t\t200: roleResponseSchema,\n\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t400: validateBadRequestErrorResponse,\n\t\t},\n\t},\n\tasync function action() {\n\t\tif (!License.hasModule('custom-roles')) {\n\t\t\tthrow new Meteor.Error('error-action-not-allowed', 'This is an enterprise feature');\n\t\t}\n\n\t\tconst { userId } = this;\n\n\t\tif (!userId || !(await hasPermissionAsync(userId, 'access-permissions'))) {\n\t\t\tthrow new Meteor.Error('error-action-not-allowed', 'Accessing permissions is not allowed');\n\t\t}\n\n\t\tconst { name, scope, description, mandatory2fa } = this.bodyParams;\n\n\t\tif (await Roles.findOneByIdOrName(name)) {\n\t\t\tthrow new Meteor.Error('error-duplicate-role-names-not-allowed', 'Role name already exists');\n\t\t}\n\n\t\tconst roleData = {\n\t\t\tdescription: description || '',\n\t\t\t...(mandatory2fa !== undefined && { mandatory2fa }),\n\t\t\tname,","sourceCodeStart":97,"sourceCodeEnd":133,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/ee/server/api/roles.ts#L97-L133","documentation":"POST /v1/roles.create is an enterprise endpoint: a route-level license gate plus an in-action License.hasModule('custom-roles') check both guard it. On Community edition, or with an enterprise license lacking the custom-roles module, creating a role throws Meteor.Error('error-action-not-allowed', 'This is an enterprise feature').","triggerScenarios":"POST /api/v1/roles.create with valid auth on a workspace whose license does not include 'custom-roles' — Community edition, expired trial, or an EE license without that module.","commonSituations":"Role-management automation written against EE later deployed on CE; license expired after scripts shipped; local dev environment without a license file.","solutions":["Install and activate an enterprise license that includes the custom-roles module","Verify the license first (workspace license banner / enterprise resources endpoint) before calling roles.create","Without a license, use only built-in roles — CE has no route for creating custom roles","Start a trial or contact sales if the feature is needed"],"exampleFix":"// before\nawait POST('/api/v1/roles.create', { name: 'auditor' }); // CE workspace → error-action-not-allowed\n\n// after: gate the call on license state\nif (!(await licenseHasModule('custom-roles'))) throw new Error('custom-roles license required');\nawait POST('/api/v1/roles.create', { name: 'auditor' });","handlingStrategy":"validation","validationCode":"import { License } from '@rocket.chat/license';\n\nconst canCreateRoles = License.hasModule('custom-roles');\nif (!canCreateRoles) {\n  throw new Error('roles.create requires an enterprise license with the custom-roles module');\n}\nawait POST('/api/v1/roles.create', payload);","typeGuard":null,"tryCatchPattern":"try {\n  await POST('/api/v1/roles.create', payload);\n} catch (error) {\n  if (error.error === 'error-action-not-allowed' && /enterprise/i.test(error.reason)) {\n    // license problem, not a code problem: surface a licensing message\n    throw new LicenseRequiredError('custom-roles');\n  }\n  throw error;\n}","preventionTips":["Gate role-management UI and automation on the workspace license state","Document which integrations require EE modules so CE deployments fail gracefully","Re-verify the license after upgrades and trial expirations"],"tags":["enterprise","license","roles","rbac"],"backgroundTag":"enterprise-license-required","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}