risingwavelabs/risingwave · error · PsqlError
Failed to parse ldap url
Error message
Failed to parse ldap url
What it means
from_ldap_url parses the configured LDAP connection string with url::Url::parse before any network activity. If the string is not a valid URL (bad scheme-less text, illegal characters, unparseable host/port), the error is wrapped as this StartupError. The library validates the scheme next, but this error fires strictly on URL syntax failure.
Solutions
- Include an explicit scheme: ldap://host:port or ldaps://host:port
- Validate with a quick parse (curl or python -c "import urllib.parse;urllib.parse.urlparse(...)") before committing the config
- Strip surrounding quotes/spaces from the configured value
- Check that the env var/secret feeding ldap_url is actually populated, not empty
Example fix
// before ldap_url = 'ldap.corp.local:636' // after ldap_url = 'ldaps://ldap.corp.local:636'
Defensive patterns
Strategy: validation
Validate before calling
fn validate_ldap_url(u: &str) -> Result<(), String> {
let parsed = url::Url::parse(u).map_err(|e| format!("invalid ldap url: {e}"))?;
match parsed.scheme() {
"ldap" | "ldaps" => Ok(()),
s => Err(format!("bad scheme: {s} (expected ldap or ldaps)")),
}
} Type guard
fn is_valid_ldap_url(u: &str) -> bool {
url::Url::parse(u).map(|p| p.scheme() == "ldap" || p.scheme() == "ldaps").unwrap_or(false)
} Try / catch
catch PsqlError::StartupError at connection-creation time and log the configured ldap_url (redacted) alongside the url::ParseError for fast diagnosis
Prevention
- Keep a validated connection-string template in deployment docs
- Validate ldap_url in config linting/startup scripts before the DB starts
- Never build the URL by naive string concatenation of host and port without a scheme
- Trim whitespace and quotes from env-supplied values before assignment
When it happens
Trigger: url::Url::parse(ldap_url) returns Err — e.g. missing scheme, spaces or control characters in the URL, invalid port, empty string
Common situations: ldap_url config field set to 'ldapserver.corp' (no ldap:// scheme); copy-paste included quotes or whitespace; port written as 'ldap:389x'; templated/interpolated variable left empty at runtime.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- Can't get fe host from url
- credentials_url must be a valid URL (s3://, file://) or an…
- {err}
- Failed to connect to LDAP server
- Failed to parse client certificate
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/c21c9b5cf3e54bb8.
Report an issue: GitHub.
Appendix: source
Thrown at src/utils/pgwire/src/ldap_auth.rs:282
LDAP_SERVER_KEY,
LDAP_PORT_KEY,
LDAP_SCHEME_KEY,
LDAP_BASE_DN_KEY,
LDAP_SEARCH_ATTRIBUTE_KEY,
LDAP_SEARCH_FILTER_KEY,
];
for param in &conflicting_params {
if options.contains_key(*param) {
return Err(PsqlError::StartupError(
format!("Cannot specify both ldapurl and {} parameter", param).into(),
));
}
}
// Parse the URL using standard URL parsing
let url = url::Url::parse(ldap_url).map_err(|e| {
PsqlError::StartupError(anyhow!(e).context("Failed to parse ldap url").into())
})?;
// Validate scheme
let scheme = url.scheme();
if scheme != "ldap" && scheme != "ldaps" {
return Err(PsqlError::StartupError(
"LDAP URL scheme must be either 'ldap' or 'ldaps'".into(),
));
}
// Extract host and port
let host = url
.host_str()
.ok_or_else(|| PsqlError::StartupError("LDAP URL must contain a host".into()))?;
let port = url
.port()
.unwrap_or_else(|| if scheme == "ldaps" { 636 } else { 389 });
View on GitHub (pinned to 6469eb736d)