{"record":{"id":"6fd002a6700b9af2","repo":"RocketChat/Rocket.Chat","slug":"error-invalid-user","errorCode":"error-invalid-user","errorMessage":"error-invalid-user","messagePattern":"error-invalid-user","errorType":"error_code","errorClass":null,"httpStatus":400,"severity":"error","filePath":"apps/meteor/ee/server/api/ldap.ts","lineNumber":32,"sourceCode":"\trequired: ['message', 'success'],\n\tadditionalProperties: false,\n});\n\nAPI.v1.post(\n\t'ldap.syncNow',\n\t{\n\t\tauthRequired: true,\n\t\tforceTwoFactorAuthenticationForNonEnterprise: true,\n\t\ttwoFactorRequired: true,\n\t\tresponse: {\n\t\t\t200: ldapSyncNowResponseSchema,\n\t\t\t400: validateBadRequestErrorResponse,\n\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t},\n\t},\n\tasync function action() {\n\t\tif (!this.userId) {\n\t\t\tthrow new Error('error-invalid-user');\n\t\t}\n\n\t\tif (!(await hasPermissionAsync(this.user, 'sync-auth-services-users'))) {\n\t\t\tthrow new Error('error-not-authorized');\n\t\t}\n\n\t\tif (settings.get('LDAP_Enable') !== true) {\n\t\t\tthrow new Error('LDAP_disabled');\n\t\t}\n\n\t\tawait LDAPEnterprise.sync();\n\t\tawait LDAPEnterprise.syncAvatarAndAbacAttributes();\n\n\t\treturn API.v1.success({\n\t\t\tmessage: 'Sync_in_progress' as const,\n\t\t});\n\t},\n);","sourceCodeStart":14,"sourceCodeEnd":50,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/ee/server/api/ldap.ts#L14-L50","documentation":"Error `error-invalid-user` thrown by ldap.syncNow when this.userId is falsy inside the action. The route declares authRequired (plus 2FA enforcement for non-EE), so in practice this fires only when authentication state is missing/inconsistent — e.g. broken auth middleware, token accepted but no user bound, or direct invocation bypassing the API wrapper.","triggerScenarios":"Calling POST /v1/ldap.syncNow without an auth token, with a token for a deleted user, or through a code path that invokes the action without the auth context populated.","commonSituations":"Scripts forgetting the X-Auth-Token/X-User-Id headers; tokens invalidated between auth and handler; tests invoking the endpoint handler directly.","solutions":["Send valid X-Auth-Token and X-User-Id headers from a real, active admin user.","Re-login to mint a fresh token if the user was recreated or the token expired.","If it persists with valid credentials, inspect custom auth middleware that may strip the user from the context."],"exampleFix":"// before\nawait fetch('/api/v1/ldap.syncNow', { method: 'POST' }); // error-invalid-user\n\n// after\nawait fetch('/api/v1/ldap.syncNow', {\n\tmethod: 'POST',\n\theaders: { 'X-Auth-Token': token, 'X-User-Id': userId, 'Content-Type': 'application/json' },\n});","handlingStrategy":"validation","validationCode":"const hasAuthContext = (userId: string | null | undefined): boolean => Boolean(userId);\n\n// ensure headers on every request\nconst headers = { 'X-Auth-Token': authToken, 'X-User-Id': userId };","typeGuard":"const isInvalidUserError = (error: unknown): boolean =>\n\tBoolean(error && typeof error === 'object' && 'message' in error && (error as Error).message.includes('error-invalid-user'));","tryCatchPattern":"try {\n\tawait POST('ldap.syncNow');\n} catch (error) {\n\tif (isInvalidUserError(error)) {\n\t\tawait relogin(); // mint fresh credentials, then retry once\n\t\treturn POST('ldap.syncNow');\n\t}\n\tthrow error;\n}","preventionTips":["Attach X-Auth-Token/X-User-Id headers to every authenticated REST call.","Use tokens belonging to active users; re-login after user re-creation.","Avoid invoking endpoint actions outside the API wrapper that populates this.userId."],"tags":["ee","ldap","authentication","rest-api"],"backgroundTag":"unauthenticated-request","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}