{"record":{"id":"c0bfca8bbb52f047","repo":"RocketChat/Rocket.Chat","slug":"error-not-allowed-c0bfca","errorCode":"error-not-allowed","errorMessage":"Not allowed","messagePattern":"Not allowed","errorType":"exception","errorClass":"Meteor.Error","httpStatus":null,"severity":"error","filePath":"apps/meteor/server/meteor-methods/users/setUserStatus.ts","lineNumber":22,"sourceCode":"import { Meteor } from 'meteor/meteor';\n\nimport { RateLimiterClass as RateLimiter } from '../../lib/RateLimiter';\nimport { settings } from '../../settings';\n\ndeclare module '@rocket.chat/ddp-client' {\n\t// eslint-disable-next-line @typescript-eslint/naming-convention\n\tinterface ServerMethods {\n\t\tsetUserStatus(statusType: IUser['status'], statusText: IUser['statusText']): void;\n\t}\n}\n\nexport const setUserStatusMethod = async (\n\tuser: Pick<IUser, '_id' | 'username' | 'name' | 'status' | 'statusDefault' | 'roles' | 'statusText'>,\n\tstatusType: IUser['status'],\n\tstatusText: IUser['statusText'],\n): Promise<void> => {\n\tif (statusText != null && !settings.get('Accounts_AllowUserStatusMessageChange')) {\n\t\tthrow new Meteor.Error('error-not-allowed', 'Not allowed', {\n\t\t\tmethod: 'setUserStatus',\n\t\t});\n\t}\n\n\tconst effectiveStatus = statusType || user.statusDefault || UserStatus.ONLINE;\n\n\tif (effectiveStatus === UserStatus.OFFLINE && !settings.get('Accounts_AllowInvisibleStatusOption')) {\n\t\tthrow new Meteor.Error('error-status-not-allowed', 'Invisible status is disabled', {\n\t\t\tmethod: 'setUserStatus',\n\t\t});\n\t}\n\n\tawait Presence.setStatus(user._id, effectiveStatus, statusText);\n};\n\nMeteor.methods<ServerMethods>({\n\tsetUserStatus: async (statusType, statusText) => {\n\t\tconst user = (await Meteor.userAsync()) as IUser;","sourceCodeStart":4,"sourceCodeEnd":40,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/meteor-methods/users/setUserStatus.ts#L4-L40","documentation":"setUserStatusMethod rejects status-message updates when Accounts_AllowUserStatusMessageChange is false. The guard is statusText != null, so ANY non-null statusText - including the empty string '' - throws while the setting is off; only undefined/null slips past.","triggerScenarios":"Meteor.call('setUserStatus', statusType, statusText) or a saveUserProfile submit with statusText: '' (a common 'clear message' pattern) on a workspace where Accounts_AllowUserStatusMessageChange is disabled.","commonSituations":"Default installs with status messages off; client UIs that send an empty string when clearing a status message; profile-save flows that always include statusText even when the user never touched it.","solutions":["Omit statusText entirely (leave it undefined, not '') when the setting is disabled","Enable Accounts_AllowUserStatusMessageChange if status messages should be allowed","Hide the status-message input when the setting is false"],"exampleFix":"// before\nMeteor.call('setUserStatus', statusType, statusText); // statusText may be ''\n\n// after\nconst payload = allowStatusMessage && statusText != null\n  ? { statusType, statusText }\n  : { statusType };\nMeteor.call('setUserStatus', payload.statusType, payload.statusText);","handlingStrategy":"validation","validationCode":"const allowStatusMessage = publicSettings['Accounts_AllowUserStatusMessageChange'] === true;\nconst payload = allowStatusMessage && statusText != null\n  ? { statusType, statusText }\n  : { statusType };\nMeteor.call('setUserStatus', payload.statusType, payload.statusText);","typeGuard":"const isStatusMessage = (v: unknown, allowed: boolean): v is string | undefined =>\n  !allowed ? v === undefined : v === undefined || typeof v === 'string';","tryCatchPattern":"catch (err) {\n  if (err instanceof Meteor.Error && err.error === 'error-not-allowed') {\n    showNotice('Status messages are disabled on this server');\n  }\n}","preventionTips":["Never send statusText: '' to clear a message on servers with the feature off - omit the field instead","Read Accounts_AllowUserStatusMessageChange from public settings before rendering the status-message input","In saveUserProfile payloads, only include statusText when the user actually changed it"],"tags":["meteor","presence","settings","status"],"backgroundTag":"feature-disabled-by-setting","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}