# Major Bug or by design?

**URL:** <https://forums.rocket.chat/t/major-bug-or-by-design/12952>\
**Category:** Community Support\
**Created:** [December 30, 2021, 6:28pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952 "2021-12-30T18:28:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![tman](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tman](https://forums.rocket.chat/u/tman)\
**Post date:** [December 30, 2021, 6:28pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/1 "2021-12-30T18:28:27Z")

</div>

Hello Community. I am checking out RocketChat for the first time. I’m trying to decide between RocketChat and Mattermost. While poking around and getting familiar with RocketChat, I may have found a major bug. Please advise.

### Description

Normal user with only user permissions is allowed to create a Private Team without Administrator able to discover, view, join, or maintain!

### Server Setup Information

- Version of Rocket.Chat Server: 4.2.2
- Operating System: Ubuntu 20.04.3
- Deployment Method: manual
- Number of Running Instances: 1
- DB Replicaset Oplog: 4.4.10 / wiredTiger (oplog Enabled)
- NodeJS Version: v12.22.8
- MongoDB Version: 4.4.10 / wiredTiger (oplog Enabled)
- Proxy: apache
- Firewalls involved:

### Any additional Information

- Newly installed RocketChat server.
- Permissions settings: **create-team** _user_ is set as default.

### How to Recreate

This assumes that permissions for user has create-team (in my instance, this was default to true after install)

1. Create a normal user.
2. Login as user.
3. Click Create New button, select Team.
4. Choose to make Team private. Do not add Admin user to Team.
5. Logout of normal user and login with user with Admin privilege.
6. User created Team…
  - does not show up in Teams list for Admin.
  - is not discoverable.
  - does not show up in the Administration console under **#Rooms** section.

This flaw appears to be able to allow a normal user to take over a server with Private Teams, Channels, Rooms, etc… without oversight and knowledge that these channels exists by an Administrator.

Thanks all.

---

<div class="post-metadata">

**Author:** ![dudanogueira](https://sea1.discourse-cdn.com/flex021/user_avatar/forums.rocket.chat/dudanogueira/32/2529_2.png) [@dudanogueira](https://forums.rocket.chat/u/dudanogueira)\
**Post date:** [December 30, 2021, 8:02pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/2 "2021-12-30T20:02:55Z")

</div>

Hi! Welcome to our forums!!

Hope you choose Rocket.Chat 😉

I believe this is by design.

We have a very powerful and robust permissions system (Admin \> Permissions), and once a regular user has the create-team and create private channel permissions, they can do it.

You can avoid this by setting permissions accordingly.

By the default, a regular user can both create teams and private channels.

The idea is to be very flexible and be able to support different scenarios, including when users can create their teams and private channels as they wish.

Let me know if you have any other doubts and feel free to ping me on our open server:

> **[Rocket.Chat](https://open.rocket.chat/direct/duda.nogueira)**

Happy new year!! 🍾

---

<div class="post-metadata">

**Author:** ![tman](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tman](https://forums.rocket.chat/u/tman)\
**Post date:** [December 30, 2021, 8:48pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/3 "2021-12-30T20:48:24Z")

</div>

Thanks for the feedback. I wonder if having this as a default setting is wise. I can see this catching Admins off guard. Users come and go, as an Admin, how would I know to clean, audit, archive, maintain my server if I don’t even know teams and channels of former users exist? Is there a way for Admins to auto-join created teams/channels?

I love the flexibility though. Playing around with the permissions settings allows me to work around this. I do appreciate the flexibility (unlike Mattermost). Looking forward to learning more about Rocket.Chat.

Thanks again and Happy new year!

---

<div class="post-metadata">

**Author:** ![dudanogueira](https://sea1.discourse-cdn.com/flex021/user_avatar/forums.rocket.chat/dudanogueira/32/2529_2.png) [@dudanogueira](https://forums.rocket.chat/u/dudanogueira)\
**Post date:** [December 31, 2021, 11:01am UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/4 "2021-12-31T11:01:12Z")

</div>

As an admin, you can go to:

Admin \> Rooms

find the private room created by a user. You can delete it.  
Or you can disable the private property. And then just join it 🕶

AFAIK, there is no builtin way to auto add admins in into newly created private channels.

However, with the flexibility Rocket.Chat provides, you can easily create some scripts to accomplish that 🙂

bear in mind that conversations with E2E enabled, not even the admin will be able to read it. For better or for worse 🙂

---

<div class="post-metadata">

**Author:** ![tman](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tman](https://forums.rocket.chat/u/tman)\
**Post date:** [December 31, 2021, 9:17pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/5 "2021-12-31T21:17:22Z")

</div>

> [@dudanogueira](#):
>
> Admin \> Rooms
> 
> find the private room created by a user. You can delete it.  
> Or you can disable the private property. And then just join it 🕶

Hmmm…This is why I thought it was a bug. I am unable to discover User’s private channels. They do not show up in the Rooms Admin.

---

<div class="post-metadata">

**Author:** ![dudanogueira](https://sea1.discourse-cdn.com/flex021/user_avatar/forums.rocket.chat/dudanogueira/32/2529_2.png) [@dudanogueira](https://forums.rocket.chat/u/dudanogueira)\
**Post date:** [January 3, 2022, 1:09pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/6 "2022-01-03T13:09:07Z")

</div>

You may be right on this one.

I just tested the rooms list UI, and something is broken there at the filtering feature. I can see, for example, that the teams came from the API, but it’s not showing on the list:

 ![image](https://us1.discourse-cdn.com/flex021/uploads/rocketchat/original/2X/7/78115741319e5cd410ce509cb15df0cb4697b01a.png)

I’ll do some more tests, and check if there isn’t already an open issues or PR at our github for that.

FWIW, we have been changing a lot of the UI components recently to React, and some UI issues are expected and is being fixed really fast.

---

<div class="post-metadata">

**Author:** ![tman](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tman](https://forums.rocket.chat/u/tman)\
**Post date:** [January 5, 2022, 4:26pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/7 "2022-01-05T16:26:19Z")

</div>

Any updates? Did you find an outstanding issue on this? Any work-arounds other than disabling Team/Channel creation for Users? Thanks again for your attention!

---

<div class="post-metadata">

**Author:** ![dudanogueira](https://sea1.discourse-cdn.com/flex021/user_avatar/forums.rocket.chat/dudanogueira/32/2529_2.png) [@dudanogueira](https://forums.rocket.chat/u/dudanogueira)\
**Post date:** [January 5, 2022, 11:01pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/8 "2022-01-05T23:01:18Z")

</div>

Hi!

I think we are talking about different things 🙂  
There was a bug for filtering rooms in admin \> rooms.

This is now fixed on latest 4.3.1 already:

> <https://github.com/RocketChat/Rocket.Chat/pull/23970/>
>
> Added types into filter as it was always coming out to be undefined.
> \<!-- Your …Pull Request name should start with one of the following tags
> \[NEW\] For new features
> \[IMPROVE\] For an improvement (performance or little improvements) in existing features
> \[FIX\] For bug fixes that affect the end-user
> \[BREAK\] For pull requests including breaking changes
> Chore: For small tasks
> Doc: For documentation
> \--\>
> 
> \<!-- Checklist!!! If you're unsure about any of them, don't hesitate to ask. We're here to help! This is simply a reminder of what we are going to look for before merging your code. 
> - I have read the Contributing Guide - https://github.com/RocketChat/Rocket.Chat/blob/develop/.github/CONTRIBUTING.md#contributing-to-rocketchat doc
> - I have signed the CLA - https://cla-assistant.io/RocketChat/Rocket.Chat
> - Lint and unit tests pass locally with my changes
> - I have added tests that prove my fix is effective or that my feature works (if applicable)
> - I have added necessary documentation (if applicable)
> - Any dependent changes have been merged and published in downstream modules
> \--\>
> 
> \## Proposed changes (including videos or screenshots)
> 
> \<!--
> Describe the big picture of your changes here to communicate to the maintainers why we should accept this pull request.
> If it fixes a bug or resolves a feature request, be sure to link to that issue below.
> This description will appear in the release notes if we accept the contribution.
> \--\>
> Now,
> 
> https://user-images.githubusercontent.com/73601258/146380812-d3aa5561-64e1-4515-a639-3b6d87432ae4.mp4
> 
> Before,
> 
> https://user-images.githubusercontent.com/73601258/146385538-85a70fce-9974-40e0-8757-eda1a5d411b7.mp4
> 
> 
> 
> 
> \## Issue(s)
> 
> Closes #23955

Now you can filter and edit rooms, teams, and others.

But I think this will fix your issue.

You can let users create teams, and inspect if they are creating at the Admin \> Rooms UI.

Or you can deny them this permission in Admin \> Permissions.

Thanks!!

---

<div class="post-metadata">

**Author:** ![tman](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tman](https://forums.rocket.chat/u/tman)\
**Post date:** [January 6, 2022, 4:00pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/9 "2022-01-06T16:00:27Z")

</div>

The latest 4.3.1 has fixed the Issue as described in the thread. An Admin account can now see **all** Private Teams and Channels created by regular User accounts while in the Administration page (console).

I’d like to give my appreciation to all Rocket.Chat devs and contributors who work to bring us this awesome app. Thanks a ton!

As a side note, is there a link or a place we can go to donate to the project?

---

<div class="post-metadata">

**Author:** ![dudanogueira](https://sea1.discourse-cdn.com/flex021/user_avatar/forums.rocket.chat/dudanogueira/32/2529_2.png) [@dudanogueira](https://forums.rocket.chat/u/dudanogueira)\
**Post date:** [January 6, 2022, 4:22pm UTC](https://forums.rocket.chat/t/major-bug-or-by-design/12952/10 "2022-01-06T16:22:47Z")

</div>

Thank you a lot! We really appreciate it!

Hopefully this will get a closure to your platform evaluation and decision 😉

You can sponsor our project here: [Sponsor @RocketChat on GitHub Sponsors · GitHub](https://github.com/sponsors/RocketChat)

Thank you again!!
