{"record":{"id":"bcd1cd31c9eae853","repo":"RocketChat/Rocket.Chat","slug":"error-not-allowed-bcd1cd","errorCode":"error-not-allowed","errorMessage":"WebDAV Integration Not Allowed","messagePattern":"WebDAV Integration Not Allowed","errorType":"exception","errorClass":"Meteor.Error","httpStatus":null,"severity":"error","filePath":"apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts","lineNumber":25,"sourceCode":"\nimport { settings } from '../../../settings';\nimport { WebdavClientAdapter } from '../lib/webdavClientAdapter';\n\ndeclare module '@rocket.chat/ddp-client' {\n\t// eslint-disable-next-line @typescript-eslint/naming-convention\n\tinterface ServerMethods {\n\t\taddWebdavAccount(formData: IWebdavAccountPayload): boolean;\n\t\taddWebdavAccountByToken(data: IWebdavAccountPayload): boolean;\n\t}\n}\n\nexport const addWebdavAccountByToken = async (userId: string, data: IWebdavAccountPayload): Promise<boolean> => {\n\tif (!userId) {\n\t\tthrow new Meteor.Error('error-invalid-user', 'Invalid User', { method: 'addWebdavAccount' });\n\t}\n\n\tif (!settings.get('Webdav_Integration_Enabled')) {\n\t\tthrow new Meteor.Error('error-not-allowed', 'WebDAV Integration Not Allowed', {\n\t\t\tmethod: 'addWebdavAccount',\n\t\t});\n\t}\n\n\tcheck(\n\t\tdata,\n\t\tMatch.ObjectIncluding({\n\t\t\tserverURL: String,\n\t\t\ttoken: Match.ObjectIncluding({\n\t\t\t\taccess_token: String,\n\t\t\t\ttoken_type: String,\n\t\t\t\trefresh_token: Match.Optional(String),\n\t\t\t}),\n\t\t\tname: Match.Maybe(String),\n\t\t}),\n\t);\n\n\ttry {","sourceCodeStart":7,"sourceCodeEnd":43,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/bridges/webdav/methods/addWebdavAccount.ts#L7-L43","documentation":"The token-based WebDAV account helper throws error-not-allowed ('WebDAV Integration Not Allowed') when the Webdav_Integration_Enabled setting is false. The check runs right after the userId check, before any validation of the token data, so the whole OAuth-based WebDAV flow is gated on the workspace-level toggle.","triggerScenarios":"Calling addWebdavAccountByToken (helper or DDP method) while Webdav_Integration_Enabled is false or unset — e.g. the admin never turned on WebDAV Integration, or it was disabled after accounts were set up.","commonSituations":"Fresh installs where WebDAV was never enabled; users finding the WebDAV UI before the admin flips the setting; the setting being reset during a migration or configuration restore.","solutions":["Enable WebDAV Integration under Admin → WebDAV Integration (Webdav_Integration_Enabled = true)","Gate the WebDAV UI on the setting so users cannot reach the flow while it is off","If a script drives account creation, read the setting first and skip gracefully when disabled"],"exampleFix":"// before\nawait call('addWebdavAccountByToken', data); // throws error-not-allowed\n\n// after — verify the workspace toggle first\nconst res = await fetch('/api/v1/settings/Webdav_Integration_Enabled', { headers });\nconst { value } = await res.json();\nif (value !== true) throw new Error('Enable WebDAV Integration first');\nawait call('addWebdavAccountByToken', data);","handlingStrategy":"validation","validationCode":"const res = await fetch('/api/v1/settings/Webdav_Integration_Enabled', { headers: adminHeaders });\nconst { value } = await res.json();\nif (value !== true) throw new Error('Enable WebDAV Integration first');\nawait call('addWebdavAccountByToken', data);","typeGuard":null,"tryCatchPattern":"try {\n  await Meteor.callAsync('addWebdavAccountByToken', data);\n} catch (e) {\n  if (e.error === 'error-not-allowed') {\n    // WebDAV integration is off: hide the flow and notify the admin\n  }\n}","preventionTips":["Gate the entire WebDAV UI on Webdav_Integration_Enabled","Scripts should read the setting before attempting account creation","Treat error-not-allowed in this flow as a configuration issue, not a bug"],"tags":["meteor","webdav","settings","feature-flag"],"backgroundTag":"integration-disabled","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}