{"record":{"id":"edebc7cbc763a918","repo":"RocketChat/Rocket.Chat","slug":"error-not-allowed-edebc7","errorCode":"error-not-allowed","errorMessage":"Not allowed","messagePattern":"Not allowed","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/roles.ts","lineNumber":193,"sourceCode":"\t\t},\n\t\tasync function action() {\n\t\t\tconst { roomId, role } = this.queryParams;\n\t\t\tconst { offset, count = 50 } = await getPaginationItems(this.queryParams);\n\n\t\t\tconst projection = {\n\t\t\t\tname: 1,\n\t\t\t\tusername: 1,\n\t\t\t\temails: 1,\n\t\t\t\tavatarETag: 1,\n\t\t\t\tcreatedAt: 1,\n\t\t\t\t_updatedAt: 1,\n\t\t\t};\n\n\t\t\tif (!role) {\n\t\t\t\tthrow new Meteor.Error('error-param-not-provided', 'Query param \"role\" is required');\n\t\t\t}\n\t\t\tif (roomId && !(await hasPermissionAsync(this.user, 'view-other-user-channels'))) {\n\t\t\t\tthrow new Meteor.Error('error-not-allowed', 'Not allowed');\n\t\t\t}\n\n\t\t\tconst options = { projection: { _id: 1 } };\n\t\t\tconst roleData = await Roles.findOneById<Pick<IRole, '_id'>>(role, options);\n\n\t\t\tif (!roleData) {\n\t\t\t\tthrow new Meteor.Error('error-invalid-roleId');\n\t\t\t}\n\n\t\t\tconst { cursor, totalCount } = await getUsersInRolePaginated(roleData._id, roomId, {\n\t\t\t\tlimit: count,\n\t\t\t\tsort: { username: 1 },\n\t\t\t\tskip: offset,\n\t\t\t\tprojection,\n\t\t\t});\n\n\t\t\tconst [users, total] = await Promise.all([cursor.toArray(), totalCount]);\n","sourceCodeStart":175,"sourceCodeEnd":211,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/roles.ts#L175-L211","documentation":"Thrown by GET /api/v1/roles.getUsersInRole when a `roomId` query param is supplied and the caller lacks the view-other-user-channels permission. The endpoint itself only demands access-permissions; narrowing results to a room additionally requires being able to see other users' channel memberships — a scoped permission admins often forget to grant.","triggerScenarios":"GET /api/v1/roles.getUsersInRole?role=<id>&roomId=<rid> as a user with access-permissions but without view-other-user-channels. Omitting roomId returns the role's users across scopes and never triggers this.","commonSituations":"Custom admin dashboards where the service account has permission management rights but not channel-visibility rights; new workspaces where view-other-user-channels was revoked from the admin's role set; scripts copied between instances with divergent permission sets.","solutions":["Grant the caller's role the view-other-user-channels permission (Administration > Permissions)","If you don't strictly need room scoping, drop the roomId param","For service accounts, prefer a role that mirrors the full admin permission set rather than hand-picking"],"exampleFix":"// before\nawait sdk.get('roles.getUsersInRole', { role, roomId });\n\n// after (only scope by room when you hold the permission)\nawait sdk.get('roles.getUsersInRole', hasPermission('view-other-user-channels') ? { role, roomId } : { role });","handlingStrategy":"validation","validationCode":"// only scope by room when the session user actually holds the permission\nconst canSeeOtherChannels = me.permissions?.includes('view-other-user-channels');\nawait sdk.get('roles.getUsersInRole', canSeeOtherChannels ? { role, roomId } : { role });","typeGuard":null,"tryCatchPattern":"catch 'error-not-allowed' and fall back to the unscoped call (drop roomId) if room-scoped results are optional for your use case; otherwise surface a clear 'missing view-other-user-channels' configuration message.","preventionTips":["Document which extra permissions each roomId-using endpoint needs","Keep service-account permission sets in sync with endpoint requirements","Default to unscoped queries unless room filtering is essential"],"tags":["roles","permissions","query-params","authorization","rest-api"],"backgroundTag":"permission-denied","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}