{"record":{"id":"e340638a4079887e","repo":"RocketChat/Rocket.Chat","slug":"the-setting-id-is-not-readable","errorCode":null,"errorMessage":"The setting \"${id}\" is not readable.","messagePattern":"The setting \"(.+?)\" is not readable\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"apps/meteor/app/apps/server/bridges/settings.ts","lineNumber":27,"sourceCode":"\nexport class AppSettingBridge extends ServerSettingBridge {\n\tconstructor(private readonly orch: IAppServerOrchestrator) {\n\t\tsuper();\n\t}\n\n\tprotected async getAll(appId: string): Promise<Array<ISetting>> {\n\t\tthis.orch.debugLog(`The App ${appId} is getting all the settings.`);\n\n\t\tconst settings = await Settings.find({ secret: false }).toArray();\n\t\treturn settings.map((s) => this.orch.getConverters()?.get('settings').convertToApp(s));\n\t}\n\n\tprotected async getOneById(id: string, appId: string): Promise<ISetting> {\n\t\tthis.orch.debugLog(`The App ${appId} is getting the setting by id ${id}.`);\n\n\t\tconst setting = await this.getReadableSettingById(id, appId);\n\t\tif (!setting) {\n\t\t\tthrow new Error(`The setting \"${id}\" is not readable.`);\n\t\t}\n\n\t\treturn setting;\n\t}\n\n\tprotected async hideGroup(name: string, appId: string): Promise<void> {\n\t\tthis.orch.debugLog(`The App ${appId} is hidding the group ${name}.`);\n\n\t\tthrow new Error('Method not implemented.');\n\t}\n\n\tprotected async hideSetting(id: string, appId: string): Promise<void> {\n\t\tthis.orch.debugLog(`The App ${appId} is hidding the setting ${id}.`);\n\n\t\tif (!(await this.isReadableById(id, appId))) {\n\t\t\tthrow new Error(`The setting \"${id}\" is not readable.`);\n\t\t}\n","sourceCodeStart":9,"sourceCodeEnd":45,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/app/apps/server/bridges/settings.ts#L9-L45","documentation":"getOneById on the settings bridge returns readable settings only. getReadableSettingById returns null when the app is unknown to the manager, the setting id does not exist, the setting is hidden while the app lacks the 'server-setting.read' permission (or that permission does not allowlist the id in hiddenSettings), or the app declares no permissions at all (then only non-hidden settings are readable). All of these surface as 'The setting ... is not readable.'","triggerScenarios":"App reads a hidden server setting (e.g. credentials) without declaring 'server-setting.read' with the id in hiddenSettings; app reads a setting id that does not exist on this server version; app code runs under an appId the manager no longer knows (uninstalled mid-flight).","commonSituations":"Apps trying to read SMTP/LDAP/OAuth secrets; settings renamed or removed between Rocket.Chat versions; permission block missing from the app manifest.","solutions":["Confirm the setting id exists on this server version (Administration > Workspace > Settings, or the settings source).","Declare a permission { name: 'server-setting.read', hiddenSettings: ['<setting-id>'] } in the app manifest and reinstall the app.","For the app's own configuration, use the app-settings API instead of server settings; secret settings are never readable by apps."],"exampleFix":"// before - manifest has no permissions, app reads a hidden setting\nconst setting = await this.read.getSettingReader().getById('LDAP_Password'); // throws\n\n// after - app.json declares the permission\n// 'permissions': [{ 'name': 'server-setting.read', 'hiddenSettings': ['LDAP_Password'] }]\nconst setting = await this.read.getSettingReader().getById('LDAP_Password');","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"Catch the 'is not readable' message, log the setting id, and branch: unknown id -> fix the id; hidden setting -> declare server-setting.read with hiddenSettings; secret -> give up, secrets are never readable.","preventionTips":["Declare 'server-setting.read' (with hiddenSettings entries) in the manifest up front if you read server settings.","Prefer app settings for app configuration.","Audit setting ids after each Rocket.Chat server upgrade."],"tags":["apps-engine","settings","permissions","hidden-settings"],"backgroundTag":"setting-not-readable","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}