{"record":{"id":"9d42ef8f81b00f53","repo":"RocketChat/Rocket.Chat","slug":"error-not-allowed-9d42ef","errorCode":"error-not-allowed","errorMessage":"error-not-allowed","messagePattern":"error-not-allowed","errorType":"exception","errorClass":"Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/push.ts","lineNumber":320,"sourceCode":"\t\t\tconst { id } = this.queryParams;\n\n\t\t\tconst receiver = await Users.findOneById(this.userId);\n\t\t\tif (!receiver) {\n\t\t\t\tthrow new Error('error-user-not-found');\n\t\t\t}\n\n\t\t\tconst message = await Messages.findOneById(id);\n\t\t\tif (!message) {\n\t\t\t\tthrow new Error('error-message-not-found');\n\t\t\t}\n\n\t\t\tconst room = await Rooms.findOneById(message.rid);\n\t\t\tif (!room) {\n\t\t\t\tthrow new Error('error-room-not-found');\n\t\t\t}\n\n\t\t\tif (!(await canAccessRoomAsync(room, receiver))) {\n\t\t\t\tthrow new Error('error-not-allowed');\n\t\t\t}\n\n\t\t\tconst data = await PushNotification.getNotificationForMessageId({ receiver, room, message });\n\n\t\t\treturn API.v1.success({ data });\n\t\t},\n\t)\n\t.get(\n\t\t'push.info',\n\t\t{\n\t\t\tauthRequired: true,\n\t\t\tresponse: {\n\t\t\t\t200: pushInfoResponseSchema,\n\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t},\n\t\t},\n\t\tasync function action() {\n\t\t\tconst defaultGateway = (await Settings.findOneById('Push_gateway', { projection: { packageValue: 1 } }))?.packageValue;","sourceCodeStart":302,"sourceCodeEnd":338,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/push.ts#L302-L338","documentation":"Thrown by GET /api/v1/push.get when the receiver, message, and room all exist but canAccessRoomAsync(room, receiver) is false — the authenticated user is not allowed to read that room. Typical case: requesting push info for a message in a livechat room the user is not part of, a private channel they were removed from, or a DM they are not a party to.","triggerScenarios":"GET /api/v1/push.get?id=<messageId> for a message in a room the caller was kicked out of, another user's DM, or a livechat conversation they never served; forwarding message ids between users and fetching notifications cross-user.","commonSituations":"User removed from a private channel but the mobile client still shows a cached notification; shared queues where one agent taps a notification routed to another agent; ids leaked between sessions in a shared test harness.","solutions":["Only open notifications whose push payload targets the current user","If the user was removed from the room, clear their cached notifications on membership change events","For service usage, run with an account that legitimately has access (e.g. the room's agent or an admin with the right scope)"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// verify the current user can see the room before fetching its push info\nconst { rooms } = await sdk.get('rooms.get');\nconst canAccess = rooms.some((r) => r._id === rid);\nif (!canAccess) throw new Error(`user has no access to room ${rid}`);","typeGuard":null,"tryCatchPattern":"catch 'error-not-allowed' and hide the notification from the UI (the user lost access — e.g. removed from the channel); never retry the same id for the same user.","preventionTips":["Clear cached notifications when membership/subscription removal events arrive","Bind notifications to the receiving user id and re-check before opening","Don't forward push payloads between accounts"],"tags":["push","notifications","permissions","authorization","rooms"],"backgroundTag":"permission-denied","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}