{"record":{"id":"bf9c5997d81c3f4b","repo":"RocketChat/Rocket.Chat","slug":"error-not-allowed-bf9c59","errorCode":null,"errorMessage":"error-not-allowed","messagePattern":"error-not-allowed","errorType":"exception","errorClass":"Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/omnichannel/room.ts","lineNumber":430,"sourceCode":"\t\t\t\tthrow new Error('error-invalid-user');\n\t\t\t}\n\n\t\t\tconst room = await LivechatRooms.findOneById(roomId);\n\n\t\t\tif (!room) {\n\t\t\t\tthrow new Error('error-invalid-room');\n\t\t\t}\n\n\t\t\tif (!room.open) {\n\t\t\t\tthrow new Error('room-closed');\n\t\t\t}\n\n\t\t\tif (!(await Omnichannel.isWithinMACLimit(room))) {\n\t\t\t\tthrow new Error('error-mac-limit-reached');\n\t\t\t}\n\n\t\t\tif (!(await canAccessRoomAsync(room, user))) {\n\t\t\t\tthrow new Error('error-not-allowed');\n\t\t\t}\n\n\t\t\tawait addUserToRoom(roomId, user);\n\n\t\t\treturn API.v1.success();\n\t\t},\n\t},\n);\n\nAPI.v1.addRoute(\n\t'livechat/room.saveInfo',\n\t{ authRequired: true, permissionsRequired: ['view-l-room'], validateParams: isLiveChatRoomSaveInfoProps },\n\t{\n\t\tasync post() {\n\t\t\tconst { roomData, guestData } = this.bodyParams;\n\t\t\tconst room = await LivechatRooms.findOneById(roomData._id);\n\t\t\tif (!room || !isOmnichannelRoom(room)) {\n\t\t\t\tthrow new Error('error-invalid-room');","sourceCodeStart":412,"sourceCodeEnd":448,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/omnichannel/room.ts#L412-L448","documentation":"Thrown by GET /api/v1/livechat/room.join when canAccessRoomAsync(room, user) resolves false. The room exists, is open, and MAC limits allow the join, but this particular authenticated user is not permitted to access this omnichannel room (despite holding the route-level view-l-room permission).","triggerScenarios":"An agent outside the room's unit/department restrictions joining a conversation scoped to another unit; users without the livechat-agent role or without membership trying to join; deployments using livechat delegation/units that scope room visibility.","commonSituations":"Multi-unit installs where agents see only their unit's conversations; agents attempting to join inquiries routed to a department they do not belong to; custom agent desks assuming all agents can join any open room.","solutions":["Give the user access: add them to the room's unit/department or assign the appropriate livechat roles/permissions","Verify with an admin what canAccessRoom evaluates for that user/room pair (units, departments, roles)","If broad monitoring is intended, grant the permission set that omnichannel monitors use (e.g. view-livechat-rooms / monitor arrangements) instead of relying on join"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try { await joinRoom(roomId); } catch (e) { if (e.message === 'error-not-allowed') { showNeedsAccessMessage(roomId); return; } throw e; }","preventionTips":["Pre-assign agents to the units/departments whose rooms they must join","Do not assume view-l-room grants access to every room — units/departments scope it","Use monitor-oriented permission sets for oversight workflows"],"tags":["omnichannel","livechat","authorization","units","rest-api"],"backgroundTag":"permission-denied","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}