{"record":{"id":"dcec340c339e1de7","repo":"RocketChat/Rocket.Chat","slug":"error-abac-not-enabled","errorCode":"error-abac-not-enabled","errorMessage":"error-abac-not-enabled","messagePattern":"error-abac-not-enabled","errorType":"error_code","errorClass":null,"httpStatus":400,"severity":"error","filePath":"apps/meteor/ee/server/api/abac/index.ts","lineNumber":69,"sourceCode":"\t\t'abac/rooms/:rid/attributes',\n\t\t{\n\t\t\tauthRequired: true,\n\t\t\tpermissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],\n\t\t\tbody: POSTRoomAbacAttributesBodySchema,\n\t\t\tresponse: {\n\t\t\t\t200: GenericSuccessSchema,\n\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t\t400: GenericErrorSchema,\n\t\t\t\t403: validateUnauthorizedErrorResponse,\n\t\t\t},\n\t\t\tlicense: ['abac'],\n\t\t},\n\t\tasync function action() {\n\t\t\tconst { rid } = this.urlParams;\n\t\t\tconst { attributes } = this.bodyParams;\n\n\t\t\tif (!settings.get('ABAC_Enabled')) {\n\t\t\t\tthrow new Error('error-abac-not-enabled');\n\t\t\t}\n\n\t\t\t// This is a replace-all operation\n\t\t\t// IF you need fine grained, use the other endpoints for removing, editing & adding single attributes\n\t\t\tawait Abac.setRoomAbacAttributes(rid, attributes, getActorFromUser(this.user));\n\t\t\treturn API.v1.success();\n\t\t},\n\t)\n\t.delete(\n\t\t'abac/rooms/:rid/attributes',\n\t\t{\n\t\t\tauthRequired: true,\n\t\t\tpermissionsRequired: ['abac-management', 'manage-abac-admin-rooms'],\n\t\t\tresponse: {\n\t\t\t\t200: GenericSuccessSchema,\n\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t\t400: GenericErrorSchema,\n\t\t\t\t403: validateUnauthorizedErrorResponse,","sourceCodeStart":51,"sourceCodeEnd":87,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/ee/server/api/abac/index.ts#L51-L87","documentation":"Plain Error with message `error-abac-not-enabled` thrown by the POST abac/rooms/:rid/attributes endpoint when the ABAC_Enabled workspace setting is false at call time. The endpoint replaces ALL attributes of a room; the guard rejects the write before Abac.setRoomAbacAttributes runs. Comes back as a 400 to the REST caller.","triggerScenarios":"POST /v1/abac/rooms/:rid/attributes with a full { attributes } payload while ABAC_Enabled is off — e.g. right after license activation but before enabling the feature.","commonSituations":"Automation calling ABAC endpoints before the admin toggled ABAC on; settings reset during workspace restore; toggling ABAC off while scripts still run.","solutions":["Enable ABAC in Administration > Settings (ABAC_Enabled = true) with a valid enterprise license that includes the abac module.","Verify the license covers ABAC; without it the setting cannot be enabled.","Gate provisioning scripts on a settings check so they fail fast with a clear message instead of a 400."],"exampleFix":"// before\nawait POST('abac/rooms/GENERAL/attributes', { attributes: ['dept:eng'] }); // 400\n\n// after\nawait POST('settings/ABAC_Enabled', { value: true }); // one-time admin setup\nawait POST('abac/rooms/GENERAL/attributes', { attributes: ['dept:eng'] });","handlingStrategy":"validation","validationCode":"const abacEnabled = async (): Promise<boolean> => {\n\tconst { value } = await GET('settings/ABAC_Enabled')();\n\treturn value === true;\n};","typeGuard":"const isAbacNotEnabled = (error: unknown): boolean =>\n\tBoolean(error instanceof Error && error.message.includes('error-abac-not-enabled'));","tryCatchPattern":"try {\n\tawait POST(`abac/rooms/${rid}/attributes`, { attributes });\n} catch (error) {\n\tif (isAbacNotEnabled(error)) {\n\t\tthrow new ConfigurationError('Enable ABAC_Enabled before writing room attributes');\n\t}\n\tthrow error;\n}","preventionTips":["Run setup in order: license -> ABAC_Enabled -> attribute writes.","Preflight the setting in scripts instead of relying on the 400.","Remember this call replaces ALL room attributes — snapshot first when enabled."],"tags":["ee","abac","feature-flag","rest-api"],"backgroundTag":"feature-not-enabled","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}