RocketChat/Rocket.Chat · error · Error
LDAP_disabled
Error message
LDAP_disabled
What it means
POST /api/v1/ldap.testConnection reads the persisted LDAP_Enable setting and throws Error('LDAP_disabled') (ldap.ts:38) unless it is exactly true. The admin UI's test button hits this endpoint, and the setting must be enabled AND saved - flipping the toggle without saving, or testing during first-time setup before enabling LDAP, produces this error.
Solutions
- Enable and save LDAP first: Administration -> LDAP -> Enable, then re-run the test
- Confirm the value persisted by reading it back via the settings API or reloading the admin page
- If you must test while keeping LDAP off in production, reproduce the settings on a staging workspace instead
Defensive patterns
Strategy: validation
Validate before calling
const { value: ldapEnabled } = await api.get('/api/v1/settings/LDAP_Enable'); // admin token required
if (ldapEnabled !== true) {
throw new Error('LDAP is disabled - enable and save it before running connection tests');
}
await api.post('/api/v1/ldap.testConnection'); Try / catch
try {
await api.post('/api/v1/ldap.testConnection');
} catch (err) {
if (err.response?.body?.error === 'LDAP_disabled') {
showBanner('Enable LDAP in Administration -> LDAP and save before testing');
return;
}
throw err;
} Prevention
- In setup wizards, require Enable-LDAP to be saved before exposing the test button
- Automations should read LDAP_Enable first and skip the test instead of calling it blindly
When it happens
Trigger: LDAP_Enable false (fresh install or never enabled); toggled in the admin UI but not persisted; LDAP deliberately disabled for maintenance while an automation still runs the test.
Common situations: Admins testing the connection during initial LDAP setup before saving 'Enable LDAP'; automated health checks that keep testing after LDAP was turned off.
Related errors
- error-endpoint-disabled
- error-endpoint-disabled
- error-id-param-not-provided
- error-invalid-user
- error-invalid-user
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/df8aed16d9e80807.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/ldap.ts:38
API.v1.post(
'ldap.testConnection',
{
authRequired: true,
permissionsRequired: ['test-admin-options'],
response: {
200: ajv.compile<{ message: string; success: true }>(messageResponseSchema),
401: validateUnauthorizedErrorResponse,
403: validateForbiddenErrorResponse,
},
},
async function action() {
if (!this.userId) {
throw new Error('error-invalid-user');
}
if (settings.get<boolean>('LDAP_Enable') !== true) {
throw new Error('LDAP_disabled');
}
try {
await LDAP.testConnection();
} catch (err) {
SystemLogger.error({ err });
throw new Error('Connection_failed');
}
return API.v1.success({
message: 'LDAP_Connection_successful' as const,
});
},
);
API.v1.post(
'ldap.testSearch',
{View on GitHub (pinned to b2c16d5842)