{"record":{"id":"b529f2b6e2eccf3e","repo":"RocketChat/Rocket.Chat","slug":"ldap-disabled","errorCode":"LDAP_disabled","errorMessage":"LDAP_disabled","messagePattern":"LDAP_disabled","errorType":"exception","errorClass":"Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/ee/server/api/ldap.ts","lineNumber":40,"sourceCode":"\t\tforceTwoFactorAuthenticationForNonEnterprise: true,\n\t\ttwoFactorRequired: true,\n\t\tresponse: {\n\t\t\t200: ldapSyncNowResponseSchema,\n\t\t\t400: validateBadRequestErrorResponse,\n\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t},\n\t},\n\tasync function action() {\n\t\tif (!this.userId) {\n\t\t\tthrow new Error('error-invalid-user');\n\t\t}\n\n\t\tif (!(await hasPermissionAsync(this.user, 'sync-auth-services-users'))) {\n\t\t\tthrow new Error('error-not-authorized');\n\t\t}\n\n\t\tif (settings.get('LDAP_Enable') !== true) {\n\t\t\tthrow new Error('LDAP_disabled');\n\t\t}\n\n\t\tawait LDAPEnterprise.sync();\n\t\tawait LDAPEnterprise.syncAvatarAndAbacAttributes();\n\n\t\treturn API.v1.success({\n\t\t\tmessage: 'Sync_in_progress' as const,\n\t\t});\n\t},\n);\n","sourceCodeStart":22,"sourceCodeEnd":51,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/ee/server/api/ldap.ts#L22-L51","documentation":"Error `LDAP_disabled` thrown by ldap.syncNow when the LDAP_Enable setting is not exactly true. The endpoint exists whenever the enterprise LDAP package is loaded, but refuses to start a sync against a workspace where LDAP login is switched off, since there is no configured directory to sync.","triggerScenarios":"POST /v1/ldap.syncNow after LDAP was disabled in Administration > LDAP, or before initial LDAP configuration was enabled.","commonSituations":"Sync scripts running while admins reconfigure LDAP; freshly restored workspaces where LDAP_Enable reset to default false; temporarily disabling LDAP and forgetting dependent automation.","solutions":["Enable LDAP in Administration > LDAP (LDAP_Enable = true) with a working server configuration, then retry the sync.","Pause/queue ldap.syncNow automation while LDAP is intentionally disabled.","Preflight the setting so failures surface as configuration errors, not API errors."],"exampleFix":"// before\nawait POST('ldap.syncNow'); // LDAP_disabled\n\n// after\nawait POST('settings/LDAP_Enable', { value: true });\nawait POST('ldap.syncNow');","handlingStrategy":"validation","validationCode":"const ldapEnabled = async (): Promise<boolean> => (await GET('settings/LDAP_Enable')()).value === true;","typeGuard":"const isLdapDisabled = (error: unknown): boolean =>\n\tBoolean(error && typeof error === 'object' && 'message' in error && (error as Error).message.includes('LDAP_disabled'));","tryCatchPattern":"try {\n\tawait POST('ldap.syncNow');\n} catch (error) {\n\tif (isLdapDisabled(error)) {\n\t\t// configuration problem, not transient: report and stop\n\t\tthrow new ConfigurationError('LDAP is disabled on this workspace');\n\t}\n\tthrow error;\n}","preventionTips":["Verify LDAP_Enable is true before scheduling sync jobs.","Pause directory automation while LDAP is being reconfigured.","After workspace restores, re-check that LDAP settings survived."],"tags":["ee","ldap","feature-flag","rest-api"],"backgroundTag":"feature-not-enabled","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}