phacility/phabricator · error · Exception

LDAP: Failed to retrieve record for user "%s" when searching

Error message

LDAP: Failed to retrieve record for user "%s" when searching. Credentialed users may not be able to search your LDAP server. Try configuring anonymous credentials or fully anonymous binds.

What it means

Error "LDAP: Failed to retrieve record for user "%s" when searching. Credentialed users may not be able to search your LDAP server. Try configuring anonymous credentials or fully anonymous binds." thrown in phacility/phabricator.

Source

Thrown at src/applications/auth/adapter/PhutilLDAPAuthAdapter.php:268

    $this->bindLDAP($conn, $distinguished_name, $login_pass);

    $result = $this->searchLDAPForRecord($search_query);
    if (!$result) {
      // This is unusual (since the bind succeeded) but we've seen it at least
      // once in the wild, where the anonymous user is allowed to search but
      // the credentialed user is not.

      // If we don't have anonymous credentials, raise an explicit exception
      // here since we'll fail a typehint if we don't return an array anyway
      // and this is a more useful error.

      // If we do have anonymous credentials, we'll rebind and try the search
      // again below. Doing this automatically means things work correctly more
      // often without requiring additional configuration.
      if (!$this->shouldBindWithoutIdentity()) {
        // No anonymous credentials, so we just fail here.
        throw new Exception(
          pht(
            'LDAP: Failed to retrieve record for user "%s" when searching. '.
            'Credentialed users may not be able to search your LDAP server. '.
            'Try configuring anonymous credentials or fully anonymous binds.',
            $login_user));
      } else {
        // Rebind as anonymous and try the search again.
        $user = $this->anonymousUsername;
        $pass = $this->anonymousPassword;
        $this->bindLDAP($conn, $user, $pass);

        $result = $this->searchLDAPForRecord($search_query);
        if (!$result) {
          throw new Exception(
            pht(
              'LDAP: Failed to retrieve record for user "%s" when searching '.
              'with both user and anonymous credentials.',
              $login_user));

View on GitHub (pinned to 5720a38cfe)

When it happens

Trigger: Thrown at src/applications/auth/adapter/PhutilLDAPAuthAdapter.php:268 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of phacility/phabricator@5720a38cfe (2026-08-21). Data as JSON: /api/errors/3422c573b89fd560. Report an issue: GitHub.