{"record":{"id":"1bbf38602a0db65c","repo":"RocketChat/Rocket.Chat","slug":"error-invalid-user-1bbf38","errorCode":null,"errorMessage":"error-invalid-user","messagePattern":"error-invalid-user","errorType":"exception","errorClass":"Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/ldap.ts","lineNumber":34,"sourceCode":"\t},\n\trequired: ['message', 'success'] as const,\n\tadditionalProperties: false,\n};\n\nAPI.v1.post(\n\t'ldap.testConnection',\n\t{\n\t\tauthRequired: true,\n\t\tpermissionsRequired: ['test-admin-options'],\n\t\tresponse: {\n\t\t\t200: ajv.compile<{ message: string; success: true }>(messageResponseSchema),\n\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t403: validateForbiddenErrorResponse,\n\t\t},\n\t},\n\tasync function action() {\n\t\tif (!this.userId) {\n\t\t\tthrow new Error('error-invalid-user');\n\t\t}\n\n\t\tif (settings.get<boolean>('LDAP_Enable') !== true) {\n\t\t\tthrow new Error('LDAP_disabled');\n\t\t}\n\n\t\ttry {\n\t\t\tawait LDAP.testConnection();\n\t\t} catch (err) {\n\t\t\tSystemLogger.error({ err });\n\t\t\tthrow new Error('Connection_failed');\n\t\t}\n\n\t\treturn API.v1.success({\n\t\t\tmessage: 'LDAP_Connection_successful' as const,\n\t\t});\n\t},\n);","sourceCodeStart":16,"sourceCodeEnd":52,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/ldap.ts#L16-L52","documentation":"First guard in POST /api/v1/ldap.testConnection (ldap.ts:34): throws plain Error('error-invalid-user') when this.userId is falsy at action time. The route declares authRequired: true with permissionsRequired ['test-admin-options'], so the standard auth middleware rejects unauthenticated or unauthorized requests (401/403) before the action runs. Reaching this throw means the request executed without a resolved user id - typically a customized/patched auth layer, or middleware misconfiguration.","triggerScenarios":"Calling POST /api/v1/ldap.testConnection with missing/invalid X-Auth-Token and X-User-Id on a deployment where auth middleware was altered; a token whose user cannot be resolved at action time.","commonSituations":"Expired or revoked auth tokens; reverse proxies stripping auth headers; forks that relaxed authRequired or replaced the middleware.","solutions":["Send valid credentials: X-Auth-Token + X-User-Id headers (or Authorization: Bearer) from an active session","Verify the token first with GET /api/v1/me - if that fails, re-authenticate","Ensure the account holds test-admin-options, otherwise the middleware returns 403 before this code runs","If headers are correct and you still see this, audit any custom middleware on the deployment"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"const me = await api.get('/api/v1/me');\nif (!me || !me._id) {\n  throw new Error('Session invalid - re-authenticate before calling ldap.testConnection');\n}\nawait api.post('/api/v1/ldap.testConnection');","typeGuard":null,"tryCatchPattern":"try {\n  await api.post('/api/v1/ldap.testConnection');\n} catch (err) {\n  if (err.response?.body?.error === 'error-invalid-user' || err.message === 'error-invalid-user') {\n    await reauthenticate(); // stale credentials - refresh token, then retry once\n    return api.post('/api/v1/ldap.testConnection');\n  }\n  throw err;\n}","preventionTips":["Validate sessions via /api/v1/me before admin-only calls","Refresh tokens proactively instead of waiting for failures","Ensure proxies forward auth headers untouched"],"tags":["ldap","authentication","rest-api"],"backgroundTag":"unauthenticated-request","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}