RocketChat/Rocket.Chat · error · Error

LDAP_disabled

Error message

LDAP_disabled

What it means

POST /api/v1/ldap.testConnection reads the persisted LDAP_Enable setting and throws Error('LDAP_disabled') (ldap.ts:38) unless it is exactly true. The admin UI's test button hits this endpoint, and the setting must be enabled AND saved - flipping the toggle without saving, or testing during first-time setup before enabling LDAP, produces this error.

Solutions

  1. Enable and save LDAP first: Administration -> LDAP -> Enable, then re-run the test
  2. Confirm the value persisted by reading it back via the settings API or reloading the admin page
  3. If you must test while keeping LDAP off in production, reproduce the settings on a staging workspace instead
Defensive patterns

Strategy: validation

Validate before calling

const { value: ldapEnabled } = await api.get('/api/v1/settings/LDAP_Enable'); // admin token required
if (ldapEnabled !== true) {
  throw new Error('LDAP is disabled - enable and save it before running connection tests');
}
await api.post('/api/v1/ldap.testConnection');

Try / catch

try {
  await api.post('/api/v1/ldap.testConnection');
} catch (err) {
  if (err.response?.body?.error === 'LDAP_disabled') {
    showBanner('Enable LDAP in Administration -> LDAP and save before testing');
    return;
  }
  throw err;
}

Prevention

When it happens

Trigger: LDAP_Enable false (fresh install or never enabled); toggled in the admin UI but not persisted; LDAP deliberately disabled for maintenance while an automation still runs the test.

Common situations: Admins testing the connection during initial LDAP setup before saving 'Enable LDAP'; automated health checks that keep testing after LDAP was turned off.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/df8aed16d9e80807. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/ldap.ts:38

API.v1.post(
	'ldap.testConnection',
	{
		authRequired: true,
		permissionsRequired: ['test-admin-options'],
		response: {
			200: ajv.compile<{ message: string; success: true }>(messageResponseSchema),
			401: validateUnauthorizedErrorResponse,
			403: validateForbiddenErrorResponse,
		},
	},
	async function action() {
		if (!this.userId) {
			throw new Error('error-invalid-user');
		}

		if (settings.get<boolean>('LDAP_Enable') !== true) {
			throw new Error('LDAP_disabled');
		}

		try {
			await LDAP.testConnection();
		} catch (err) {
			SystemLogger.error({ err });
			throw new Error('Connection_failed');
		}

		return API.v1.success({
			message: 'LDAP_Connection_successful' as const,
		});
	},
);

API.v1.post(
	'ldap.testSearch',
	{

View on GitHub (pinned to b2c16d5842)