{"record":{"id":"fe50b87e122da6c9","repo":"RocketChat/Rocket.Chat","slug":"unauthorized","errorCode":null,"errorMessage":"unauthorized","messagePattern":"unauthorized","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"apps/meteor/server/api/v1/channels.ts","lineNumber":1015,"sourceCode":"\t},\n);\n\nasync function createChannelValidator(params: {\n\tuser: { value: string };\n\tname?: { key: string; value?: string };\n\tmembers?: { key: string; value?: string[] };\n\tcustomFields?: { key: string; value?: string };\n\tteams?: { key: string; value?: string[] };\n\tteamId?: { key: string; value?: string };\n}) {\n\tconst teamId = params.teamId?.value;\n\n\tconst team = teamId && (await Team.getInfoById(teamId));\n\tif (\n\t\t(!teamId && !(await hasPermissionAsync(params.user.value, 'create-c'))) ||\n\t\t(teamId && team && !(await hasPermissionAsync(params.user.value, 'create-team-channel', team.roomId)))\n\t) {\n\t\tthrow new Error('unauthorized');\n\t}\n\n\tif (!params.name?.value) {\n\t\tthrow new Error(`Param \"${params.name?.key}\" is required`);\n\t}\n\n\tif (params.members?.value && !Array.isArray(params.members.value)) {\n\t\tthrow new Error(`Param \"${params.members.key}\" must be an array if provided`);\n\t}\n\n\tif (params.customFields?.value && !(typeof params.customFields.value === 'object')) {\n\t\tthrow new Error(`Param \"${params.customFields.key}\" must be an object if provided`);\n\t}\n\n\tif (params.teams?.value && !Array.isArray(params.teams.value)) {\n\t\tthrow new Error(`Param ${params.teams.key} must be an array`);\n\t}\n}","sourceCodeStart":997,"sourceCodeEnd":1033,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/e4b8178b205510181a96ceefee043d0abcd13e5a/apps/meteor/server/api/v1/channels.ts#L997-L1033","documentation":"Plain Error thrown by validateChannelParams (the shared validator for POST channels.create) when the calling user lacks permission to create channels: without a teamId you need the 'create-c' permission; with a valid teamId you need 'create-team-channel' on that team's room. Note the quirk that an unknown teamId (team lookup fails) skips the permission check rather than erroring here.","triggerScenarios":"POST /api/v1/channels.create by a user whose role lacks create-c; or with teamId supplied and a valid team where the user lacks create-team-channel; commonly a bot/CI token whose role was never granted channel-creation permissions.","commonSituations":"Newly created API users or bots with minimal roles; self-service guest roles that cannot create channels; attempting to create a channel inside a team the user only joined as a guest; custom role permission resets after an upgrade.","solutions":["Grant the user's role the create-c permission (or create-team-channel for team channels) in Administration > Permissions","Verify the authenticated user with GET /api/v1/me and check its roles before calling create","For team channels, confirm the user is a member of the target team and the role has create-team-channel on that team room"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"const me = await GET('/api/v1/me');\nconst canCreate = me.roles.includes('admin') || (await GET('/api/v1/permissions', { userId: me._id }))\n  .update.some((p) => p._id === 'create-c');","typeGuard":null,"tryCatchPattern":"try { await POST('/api/v1/channels.create', body); } catch (e) {\n  if (e.message === 'unauthorized') { /* request create-c permission grant */ }\n}","preventionTips":["Provision bot/API roles with create-c explicitly in setup scripts","Check permissions endpoints before shipping self-service channel creation UI"],"tags":["rest-api","channels","permissions","authorization","rocket-chat"],"backgroundTag":"insufficient-permissions","analyzedSha":"e4b8178b205510181a96ceefee043d0abcd13e5a","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}