{"record":{"id":"df8aed16d9e80807","repo":"RocketChat/Rocket.Chat","slug":"ldap-disabled-df8aed","errorCode":null,"errorMessage":"LDAP_disabled","messagePattern":"LDAP_disabled","errorType":"exception","errorClass":"Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/ldap.ts","lineNumber":38,"sourceCode":"\nAPI.v1.post(\n\t'ldap.testConnection',\n\t{\n\t\tauthRequired: true,\n\t\tpermissionsRequired: ['test-admin-options'],\n\t\tresponse: {\n\t\t\t200: ajv.compile<{ message: string; success: true }>(messageResponseSchema),\n\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t403: validateForbiddenErrorResponse,\n\t\t},\n\t},\n\tasync function action() {\n\t\tif (!this.userId) {\n\t\t\tthrow new Error('error-invalid-user');\n\t\t}\n\n\t\tif (settings.get<boolean>('LDAP_Enable') !== true) {\n\t\t\tthrow new Error('LDAP_disabled');\n\t\t}\n\n\t\ttry {\n\t\t\tawait LDAP.testConnection();\n\t\t} catch (err) {\n\t\t\tSystemLogger.error({ err });\n\t\t\tthrow new Error('Connection_failed');\n\t\t}\n\n\t\treturn API.v1.success({\n\t\t\tmessage: 'LDAP_Connection_successful' as const,\n\t\t});\n\t},\n);\n\nAPI.v1.post(\n\t'ldap.testSearch',\n\t{","sourceCodeStart":20,"sourceCodeEnd":56,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/ldap.ts#L20-L56","documentation":"POST /api/v1/ldap.testConnection reads the persisted LDAP_Enable setting and throws Error('LDAP_disabled') (ldap.ts:38) unless it is exactly true. The admin UI's test button hits this endpoint, and the setting must be enabled AND saved - flipping the toggle without saving, or testing during first-time setup before enabling LDAP, produces this error.","triggerScenarios":"LDAP_Enable false (fresh install or never enabled); toggled in the admin UI but not persisted; LDAP deliberately disabled for maintenance while an automation still runs the test.","commonSituations":"Admins testing the connection during initial LDAP setup before saving 'Enable LDAP'; automated health checks that keep testing after LDAP was turned off.","solutions":["Enable and save LDAP first: Administration -> LDAP -> Enable, then re-run the test","Confirm the value persisted by reading it back via the settings API or reloading the admin page","If you must test while keeping LDAP off in production, reproduce the settings on a staging workspace instead"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"const { value: ldapEnabled } = await api.get('/api/v1/settings/LDAP_Enable'); // admin token required\nif (ldapEnabled !== true) {\n  throw new Error('LDAP is disabled - enable and save it before running connection tests');\n}\nawait api.post('/api/v1/ldap.testConnection');","typeGuard":null,"tryCatchPattern":"try {\n  await api.post('/api/v1/ldap.testConnection');\n} catch (err) {\n  if (err.response?.body?.error === 'LDAP_disabled') {\n    showBanner('Enable LDAP in Administration -> LDAP and save before testing');\n    return;\n  }\n  throw err;\n}","preventionTips":["In setup wizards, require Enable-LDAP to be saved before exposing the test button","Automations should read LDAP_Enable first and skip the test instead of calling it blindly"],"tags":["ldap","settings","rest-api","disabled-feature"],"backgroundTag":"feature-disabled-by-setting","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}