RocketChat/Rocket.Chat · error · Error
error-invalid-user
Error message
error-invalid-user
What it means
First guard in POST /api/v1/ldap.testConnection (ldap.ts:34): throws plain Error('error-invalid-user') when this.userId is falsy at action time. The route declares authRequired: true with permissionsRequired ['test-admin-options'], so the standard auth middleware rejects unauthenticated or unauthorized requests (401/403) before the action runs. Reaching this throw means the request executed without a resolved user id - typically a customized/patched auth layer, or middleware misconfiguration.
Solutions
- Send valid credentials: X-Auth-Token + X-User-Id headers (or Authorization: Bearer) from an active session
- Verify the token first with GET /api/v1/me - if that fails, re-authenticate
- Ensure the account holds test-admin-options, otherwise the middleware returns 403 before this code runs
- If headers are correct and you still see this, audit any custom middleware on the deployment
Defensive patterns
Strategy: validation
Validate before calling
const me = await api.get('/api/v1/me');
if (!me || !me._id) {
throw new Error('Session invalid - re-authenticate before calling ldap.testConnection');
}
await api.post('/api/v1/ldap.testConnection'); Try / catch
try {
await api.post('/api/v1/ldap.testConnection');
} catch (err) {
if (err.response?.body?.error === 'error-invalid-user' || err.message === 'error-invalid-user') {
await reauthenticate(); // stale credentials - refresh token, then retry once
return api.post('/api/v1/ldap.testConnection');
}
throw err;
} Prevention
- Validate sessions via /api/v1/me before admin-only calls
- Refresh tokens proactively instead of waiting for failures
- Ensure proxies forward auth headers untouched
When it happens
Trigger: Calling POST /api/v1/ldap.testConnection with missing/invalid X-Auth-Token and X-User-Id on a deployment where auth middleware was altered; a token whose user cannot be resolved at action time.
Common situations: Expired or revoked auth tokens; reverse proxies stripping auth headers; forks that relaxed authRequired or replaced the middleware.
Related errors
- error-invalid-user
- error-challenge-expired
- error-challenge-not-found
- error-invalid-challenge-method
- error-invalid-user
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/1bbf38602a0db65c.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/ldap.ts:34
},
required: ['message', 'success'] as const,
additionalProperties: false,
};
API.v1.post(
'ldap.testConnection',
{
authRequired: true,
permissionsRequired: ['test-admin-options'],
response: {
200: ajv.compile<{ message: string; success: true }>(messageResponseSchema),
401: validateUnauthorizedErrorResponse,
403: validateForbiddenErrorResponse,
},
},
async function action() {
if (!this.userId) {
throw new Error('error-invalid-user');
}
if (settings.get<boolean>('LDAP_Enable') !== true) {
throw new Error('LDAP_disabled');
}
try {
await LDAP.testConnection();
} catch (err) {
SystemLogger.error({ err });
throw new Error('Connection_failed');
}
return API.v1.success({
message: 'LDAP_Connection_successful' as const,
});
},
);View on GitHub (pinned to b2c16d5842)