{"record":{"id":"6d8ad7f8916935ab","repo":"RocketChat/Rocket.Chat","slug":"error-not-allowed-6d8ad7","errorCode":"error-not-allowed","errorMessage":"Not allowed","messagePattern":"Not allowed","errorType":"exception","errorClass":"Meteor.Error","httpStatus":null,"severity":"error","filePath":"apps/meteor/ee/server/meteor-methods/removeCannedResponse.ts","lineNumber":10,"sourceCode":"import { CannedResponse } from '@rocket.chat/models';\nimport { check } from 'meteor/check';\nimport { Meteor } from 'meteor/meteor';\n\nimport { hasPermissionAsync } from '../../../server/lib/authorization/hasPermission';\nimport notifications from '../../../server/lib/notifications/core/lib/Notifications';\n\nexport const removeCannedResponse = async (uid: string, _id: string): Promise<void> => {\n\tif (!(await hasPermissionAsync(uid, 'remove-canned-responses'))) {\n\t\tthrow new Meteor.Error('error-not-allowed', 'Not allowed', {\n\t\t\tmethod: 'removeCannedResponse',\n\t\t});\n\t}\n\n\tcheck(_id, String);\n\n\tconst cannedResponse = await CannedResponse.findOneById(_id);\n\tif (!cannedResponse) {\n\t\tthrow new Meteor.Error('error-canned-response-not-found', 'Canned Response not found', {\n\t\t\tmethod: 'removeCannedResponse',\n\t\t});\n\t}\n\n\tnotifications.streamCannedResponses.emit('canned-responses', { type: 'removed', _id });\n\n\tawait CannedResponse.removeById(_id);\n};\n","sourceCodeStart":1,"sourceCodeEnd":28,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/ee/server/meteor-methods/removeCannedResponse.ts#L1-L28","documentation":"The removeCannedResponse method (apps/meteor/ee/server/meteor-methods/removeCannedResponse.ts:10) first checks hasPermissionAsync(uid, 'remove-canned-responses'); users without that permission get Meteor.Error('error-not-allowed') before the id is even validated.","triggerScenarios":"Calling the removeCannedResponse DDP method with a uid that lacks the 'remove-canned-responses' permission — e.g. livechat agents whose role only has save permissions, or regular users.","commonSituations":"Role/permission misconfiguration after enabling canned responses; admin UI removing an agent-created response while the acting admin role lost the permission; custom clients reusing a low-privilege token.","solutions":["Grant 'remove-canned-responses' to the acting user's role (Administration > Permissions)","Pre-check permission client-side to hide delete actions the user cannot perform","Use an admin/manager account for bulk cleanup of canned responses"],"exampleFix":"// before\nMeteor.call('removeCannedResponse', _id);\n\n// after\nif (!(await hasPermissionAsync(uid, 'remove-canned-responses'))) {\n\tthrow new Meteor.Error('error-not-allowed', 'Not allowed');\n}\nMeteor.call('removeCannedResponse', _id);","handlingStrategy":"validation","validationCode":"if (!(await hasPermissionAsync(uid, 'remove-canned-responses'))) {\n\tthrow new Meteor.Error('error-not-allowed', 'Not allowed');\n}\nawait removeCannedResponse(uid, _id);","typeGuard":null,"tryCatchPattern":"try {\n\tawait removeCannedResponse(uid, _id);\n} catch (e) {\n\tif (e instanceof Meteor.Error && e.error === 'error-not-allowed') {\n\t\t// hide delete actions for this user; do not retry\n\t}\n\tthrow e;\n}","preventionTips":["Check 'remove-canned-responses' before rendering delete controls","Keep canned-response permissions aligned with roles when onboarding agents","Use privileged service accounts for bulk cleanup scripts"],"tags":["canned-responses","omnichannel","permissions","meteor-method"],"backgroundTag":"permission-denied","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}