risingwavelabs/risingwave · error · PsqlError

Failed to parse ldap url

Error message

Failed to parse ldap url

What it means

from_ldap_url parses the configured LDAP connection string with url::Url::parse before any network activity. If the string is not a valid URL (bad scheme-less text, illegal characters, unparseable host/port), the error is wrapped as this StartupError. The library validates the scheme next, but this error fires strictly on URL syntax failure.

Solutions

  1. Include an explicit scheme: ldap://host:port or ldaps://host:port
  2. Validate with a quick parse (curl or python -c "import urllib.parse;urllib.parse.urlparse(...)") before committing the config
  3. Strip surrounding quotes/spaces from the configured value
  4. Check that the env var/secret feeding ldap_url is actually populated, not empty

Example fix

// before
ldap_url = 'ldap.corp.local:636'
// after
ldap_url = 'ldaps://ldap.corp.local:636'
Defensive patterns

Strategy: validation

Validate before calling

fn validate_ldap_url(u: &str) -> Result<(), String> {
    let parsed = url::Url::parse(u).map_err(|e| format!("invalid ldap url: {e}"))?;
    match parsed.scheme() {
        "ldap" | "ldaps" => Ok(()),
        s => Err(format!("bad scheme: {s} (expected ldap or ldaps)")),
    }
}

Type guard

fn is_valid_ldap_url(u: &str) -> bool {
    url::Url::parse(u).map(|p| p.scheme() == "ldap" || p.scheme() == "ldaps").unwrap_or(false)
}

Try / catch

catch PsqlError::StartupError at connection-creation time and log the configured ldap_url (redacted) alongside the url::ParseError for fast diagnosis

Prevention

When it happens

Trigger: url::Url::parse(ldap_url) returns Err — e.g. missing scheme, spaces or control characters in the URL, invalid port, empty string

Common situations: ldap_url config field set to 'ldapserver.corp' (no ldap:// scheme); copy-paste included quotes or whitespace; port written as 'ldap:389x'; templated/interpolated variable left empty at runtime.

Understand the failure class

Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/c21c9b5cf3e54bb8. Report an issue: GitHub.

Appendix: source

Thrown at src/utils/pgwire/src/ldap_auth.rs:282

            LDAP_SERVER_KEY,
            LDAP_PORT_KEY,
            LDAP_SCHEME_KEY,
            LDAP_BASE_DN_KEY,
            LDAP_SEARCH_ATTRIBUTE_KEY,
            LDAP_SEARCH_FILTER_KEY,
        ];

        for param in &conflicting_params {
            if options.contains_key(*param) {
                return Err(PsqlError::StartupError(
                    format!("Cannot specify both ldapurl and {} parameter", param).into(),
                ));
            }
        }

        // Parse the URL using standard URL parsing
        let url = url::Url::parse(ldap_url).map_err(|e| {
            PsqlError::StartupError(anyhow!(e).context("Failed to parse ldap url").into())
        })?;

        // Validate scheme
        let scheme = url.scheme();
        if scheme != "ldap" && scheme != "ldaps" {
            return Err(PsqlError::StartupError(
                "LDAP URL scheme must be either 'ldap' or 'ldaps'".into(),
            ));
        }

        // Extract host and port
        let host = url
            .host_str()
            .ok_or_else(|| PsqlError::StartupError("LDAP URL must contain a host".into()))?;
        let port = url
            .port()
            .unwrap_or_else(|| if scheme == "ldaps" { 636 } else { 389 });

View on GitHub (pinned to 6469eb736d)