{"record":{"id":"a25455dcaf2e4a7f","repo":"RocketChat/Rocket.Chat","slug":"visitor-has-open-rooms","errorCode":"visitor-has-open-rooms","errorMessage":"Cannot remove visitors with opened rooms","messagePattern":"Cannot remove visitors with opened rooms","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/omnichannel/visitor.ts","lineNumber":144,"sourceCode":"\t\tconst extraQuery = await callbacks.run('livechat.applyRoomRestrictions', {}, { userId: this.userId });\n\t\tconst rooms = await LivechatRooms.findOpenByVisitorToken(\n\t\t\tthis.urlParams.token,\n\t\t\t{\n\t\t\t\tprojection: {\n\t\t\t\t\tname: 1,\n\t\t\t\t\tt: 1,\n\t\t\t\t\tcl: 1,\n\t\t\t\t\tu: 1,\n\t\t\t\t\tusernames: 1,\n\t\t\t\t\tservedBy: 1,\n\t\t\t\t},\n\t\t\t},\n\t\t\textraQuery,\n\t\t).toArray();\n\n\t\t// if gdpr is enabled, bypass rooms check\n\t\tif (rooms?.length && !settings.get('Livechat_Allow_collect_and_store_HTTP_header_informations')) {\n\t\t\tthrow new Meteor.Error('visitor-has-open-rooms', 'Cannot remove visitors with opened rooms');\n\t\t}\n\n\t\tconst { _id } = visitor;\n\t\ttry {\n\t\t\tawait removeContactsByVisitorId({ _id });\n\t\t\treturn API.v1.success({\n\t\t\t\tvisitor: {\n\t\t\t\t\t_id,\n\t\t\t\t\tts: new Date().toISOString(),\n\t\t\t\t},\n\t\t\t});\n\t\t} catch (e) {\n\t\t\tlivechatLogger.error({ msg: 'Error removing visitor', err: e });\n\t\t\tthrow new Meteor.Error('error-removing-visitor', 'An error ocurred while deleting visitor');\n\t\t}\n\t},\n});\n","sourceCodeStart":126,"sourceCodeEnd":162,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/omnichannel/visitor.ts#L126-L162","documentation":"Thrown by DELETE /api/v1/livechat/visitor/:token when the visitor still has open (unclosed) livechat rooms and the setting Livechat_Allow_collect_and_store_HTTP_header_informations is DISABLED. Despite its name, that setting doubles as the GDPR-ish bypass: when it is enabled, the open-rooms check is skipped and deletion proceeds. So deletion is blocked only when open rooms exist AND the bypass setting is off.","triggerScenarios":"DELETE a visitor who currently has an in-progress chat, a queued room, or an on-hold conversation, while the HTTP-header-info setting is false; visitors whose rooms never closed due to inactivity timeouts being disabled.","commonSituations":"GDPR erasure automation running while conversations are active; test fixtures deleting visitors without closing their rooms first; ops teams surprised that enabling 'collect HTTP header info' changes deletion behavior.","solutions":["Close the visitor's open rooms first (agent closes chat, or close via the close endpoint/omnichannel APIs), then retry the DELETE","Alternatively enable Administration -> Omnichannel -> Livechat_Allow_collect_and_store_HTTP_header_informations to bypass the open-rooms check — accepting the privacy trade-off its name implies","For bulk erasure, schedule it for after closetimeout/office hours when rooms are naturally closed"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// with an authenticated admin token, check open rooms first\nconst rooms = await (await fetch(`${server}/api/v1/livechat/visitor/${encodeURIComponent(token)}/room`, { headers })).json();\nif (rooms?.rooms?.length > 0) throw new Error('close open rooms before deleting this visitor');\nawait fetch(`${server}/api/v1/livechat/visitor/${encodeURIComponent(token)}`, { method: 'DELETE' });","typeGuard":"const visitorHasNoOpenRooms = (b: { rooms?: unknown[] }): boolean => !Array.isArray(b.rooms) || b.rooms.length === 0;","tryCatchPattern":"const body = await (await fetch(url, { method: 'DELETE' })).json();\nif (!body.success && body.error === 'visitor-has-open-rooms') { /* close rooms (or enable bypass setting) and retry later */ }","preventionTips":["Close or wait out open conversations before running visitor erasure","Decide deliberately whether the HTTP-header-info setting stays off (blocks delete with open rooms)","Schedule GDPR deletes outside business hours when chats are closed"],"tags":["livechat","visitor","gdpr","delete","room-state","settings"],"backgroundTag":"resource-in-use","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}