{"record":{"id":"b50760eeefdfd47e","repo":"RocketChat/Rocket.Chat","slug":"error-not-allowed-b50760","errorCode":"error-not-allowed","errorMessage":"Change avatar is not allowed","messagePattern":"Change avatar is not allowed","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/users.ts","lineNumber":303,"sourceCode":"\t\t},\n\t)\n\t.post(\n\t\t'users.setAvatar',\n\t\t{\n\t\t\tauthRequired: true,\n\t\t\tbody: isUsersSetAvatarProps,\n\t\t\tresponse: {\n\t\t\t\t200: voidSuccessResponse,\n\t\t\t\t400: validateBadRequestErrorResponse,\n\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t\t403: validateForbiddenErrorResponse,\n\t\t\t},\n\t\t},\n\t\tasync function action() {\n\t\t\tconst canEditOtherUserAvatar = await hasPermissionAsync(this.user, 'edit-other-user-avatar');\n\n\t\t\tif (!settings.get('Accounts_AllowUserAvatarChange') && !canEditOtherUserAvatar) {\n\t\t\t\tthrow new Meteor.Error('error-not-allowed', 'Change avatar is not allowed', {\n\t\t\t\t\tmethod: 'users.setAvatar',\n\t\t\t\t});\n\t\t\t}\n\n\t\t\tlet user = await (async (): Promise<Pick<IUser, '_id' | 'username'> | undefined | null> => {\n\t\t\t\tif (isUserFromParams(this.bodyParams, this.userId, this.user)) {\n\t\t\t\t\treturn Users.findOneById(this.userId);\n\t\t\t\t}\n\t\t\t\tif (canEditOtherUserAvatar) {\n\t\t\t\t\treturn getUserFromParams(this.bodyParams);\n\t\t\t\t}\n\t\t\t})();\n\n\t\t\tif (!user) {\n\t\t\t\treturn API.v1.forbidden();\n\t\t\t}\n\n\t\t\tif (this.bodyParams.avatarUrl) {","sourceCodeStart":285,"sourceCodeEnd":321,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/e4b8178b205510181a96ceefee043d0abcd13e5a/apps/meteor/server/api/v1/users.ts#L285-L321","documentation":"Thrown by POST users.setAvatar when the workspace setting Accounts_AllowUserAvatarChange is false AND the caller lacks the edit-other-user-avatar permission. The check is a workspace-wide feature gate: avatar changes are disabled for regular users, and only that permission overrides the gate.","triggerScenarios":"POST users.setAvatar (self or other) on a workspace where an admin disabled Accounts_AllowUserAvatarChange, by a caller without edit-other-user-avatar; common in locked-down corporate deployments; admins testing with a non-admin token after flipping the setting.","commonSituations":"Branding policies that forbid custom avatars; compliance workspaces centralizing avatars via LDAP/AD sync; clients not feature-detecting and showing a broken avatar upload UI.","solutions":["Enable the setting: Administration > Accounts > Allow User Avatar Change (or PATCH settings/Accounts_AllowUserAvatarChange to true)","Otherwise perform avatar changes from an account holding edit-other-user-avatar","Feature-detect in the UI (fetch that setting or hide the control when unavailable) so users never hit the raw error"],"exampleFix":"// before\nui.showAvatarUpload = true; // always\n// after\nconst { value } = await sdk.get('settings', { query: { query: JSON.stringify({ _id: 'Accounts_AllowUserAvatarChange' }) } });\nui.showAvatarUpload = canEditOthers || value === true;","handlingStrategy":"validation","validationCode":"const enabled = await settingValue('Accounts_AllowUserAvatarChange');\nif (!enabled && !(await hasPermission('edit-other-user-avatar'))) throw new Error('avatar change disabled on this workspace');\nawait sdk.post('users.setAvatar', payload);","typeGuard":null,"tryCatchPattern":"catch (e) { if (e?.error === 'error-not-allowed' && e?.details?.method === 'users.setAvatar') hideAvatarUpload(); else throw e; }","preventionTips":["Feature-detect Accounts_AllowUserAvatarChange before showing upload UI","On locked-down workspaces use an account with edit-other-user-avatar for managed avatars"],"tags":["rest-api","users","avatar","permissions","workspace-settings","authorization"],"backgroundTag":"feature-disabled-by-setting","analyzedSha":"e4b8178b205510181a96ceefee043d0abcd13e5a","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}