RocketChat/Rocket.Chat · error · Error

error-invalid-user

Error message

error-invalid-user

What it means

First guard in POST /api/v1/ldap.testConnection (ldap.ts:34): throws plain Error('error-invalid-user') when this.userId is falsy at action time. The route declares authRequired: true with permissionsRequired ['test-admin-options'], so the standard auth middleware rejects unauthenticated or unauthorized requests (401/403) before the action runs. Reaching this throw means the request executed without a resolved user id - typically a customized/patched auth layer, or middleware misconfiguration.

Solutions

  1. Send valid credentials: X-Auth-Token + X-User-Id headers (or Authorization: Bearer) from an active session
  2. Verify the token first with GET /api/v1/me - if that fails, re-authenticate
  3. Ensure the account holds test-admin-options, otherwise the middleware returns 403 before this code runs
  4. If headers are correct and you still see this, audit any custom middleware on the deployment
Defensive patterns

Strategy: validation

Validate before calling

const me = await api.get('/api/v1/me');
if (!me || !me._id) {
  throw new Error('Session invalid - re-authenticate before calling ldap.testConnection');
}
await api.post('/api/v1/ldap.testConnection');

Try / catch

try {
  await api.post('/api/v1/ldap.testConnection');
} catch (err) {
  if (err.response?.body?.error === 'error-invalid-user' || err.message === 'error-invalid-user') {
    await reauthenticate(); // stale credentials - refresh token, then retry once
    return api.post('/api/v1/ldap.testConnection');
  }
  throw err;
}

Prevention

When it happens

Trigger: Calling POST /api/v1/ldap.testConnection with missing/invalid X-Auth-Token and X-User-Id on a deployment where auth middleware was altered; a token whose user cannot be resolved at action time.

Common situations: Expired or revoked auth tokens; reverse proxies stripping auth headers; forks that relaxed authRequired or replaced the middleware.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/1bbf38602a0db65c. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/ldap.ts:34

	},
	required: ['message', 'success'] as const,
	additionalProperties: false,
};

API.v1.post(
	'ldap.testConnection',
	{
		authRequired: true,
		permissionsRequired: ['test-admin-options'],
		response: {
			200: ajv.compile<{ message: string; success: true }>(messageResponseSchema),
			401: validateUnauthorizedErrorResponse,
			403: validateForbiddenErrorResponse,
		},
	},
	async function action() {
		if (!this.userId) {
			throw new Error('error-invalid-user');
		}

		if (settings.get<boolean>('LDAP_Enable') !== true) {
			throw new Error('LDAP_disabled');
		}

		try {
			await LDAP.testConnection();
		} catch (err) {
			SystemLogger.error({ err });
			throw new Error('Connection_failed');
		}

		return API.v1.success({
			message: 'LDAP_Connection_successful' as const,
		});
	},
);

View on GitHub (pinned to b2c16d5842)