mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-02-10 03:12:20 +03:00
Unable to log in using ldap after a app name change #3930
Closed
opened 2026-02-05 07:53:47 +03:00 by OVERLORD
·
3 comments
No Branch/Tag Specified
development
l10n_development
release
llm_only
vectors
v25-11
docker_env
drawio_rendering
user_permissions
ldap_host_failover
svg_image
prosemirror
captcha_example
fix/video-export
v25.12.3
v25.12.2
v25.12.1
v25.12
v25.11.6
v25.11.5
v25.11.4
v24.11.4
v25.11.3
v25.11.2
v25.11.1
v25.11
v25.07.3
v25.07.2
v25.07.1
v25.07
v25.05.2
v25.05.1
v25.05
v25.02.5
v25.02.4
v25.02.3
v25.02.2
v25.02.1
v25.02
v24.12.1
v24.12
v24.10.3
v24.10.2
v24.10.1
v24.10
v24.05.4
v24.05.3
v24.05.2
v24.05.1
v24.05
v24.02.3
v24.02.2
v24.02.1
v24.02
v23.12.3
v23.12.2
v23.12.1
v23.12
v23.10.4
v23.10.3
v23.10.2
v23.10.1
v23.10
v23.08.3
v23.08.2
v23.08.1
v23.08
v23.06.2
v23.06.1
v23.06
v23.05.2
v23.05.1
v23.05
v23.02.3
v23.02.2
v23.02.1
v23.02
v23.01.1
v23.01
v22.11.1
v22.11
v22.10.2
v22.10.1
v22.10
v22.09.1
v22.09
v22.07.3
v22.07.2
v22.07.1
v22.07
v22.06.2
v22.06.1
v22.06
v22.04.2
v22.04.1
v22.04
v22.03.1
v22.03
v22.02.3
v22.02.2
v22.02.1
v22.02
v21.12.5
v21.12.4
v21.12.3
v21.12.2
v21.12.1
v21.12
v21.11.3
v21.11.2
v21.11.1
v21.11
v21.10.3
v21.10.2
v21.10.1
v21.10
v21.08.6
v21.08.5
v21.08.4
v21.08.3
v21.08.2
v21.08.1
v21.08
v21.05.4
v21.05.3
v21.05.2
v21.05.1
v21.05
v21.04.6
v21.04.5
v21.04.4
v21.04.3
v21.04.2
v21.04.1
v21.04
v0.31.8
v0.31.7
v0.31.6
v0.31.5
v0.31.4
v0.31.3
v0.31.2
v0.31.1
v0.31.0
v0.30.7
v0.30.6
v0.30.5
v0.30.4
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.2
v0.23.1
v0.23.0
v0.22.0
v0.21.0
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.5
v0.18.4
v0.18.3
v0.18.2
v0.18.1
v0.18.0
v0.17.4
v0.17.3
v0.17.2
v0.17.1
v0.17.0
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.1
v0.13.0
v0.12.2
v0.12.1
v0.12.0
v0.11.2
v0.11.1
v0.11.0
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.6
v0.7.5
v0.7.4
v0.7.3
0.7.2
v.0.7.1
v0.7.0
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.0
Labels
Clear labels
🎨 Design
📖 Docs Update
🐛 Bug
🐛 Bug
:cat2:🐈 Possible duplicate
💿 Database
☕ Open to discussion
💻 Front-End
🐕 Support
🚪 Authentication
🌍 Translations
🔌 API Task
🏭 Back-End
⛲ Upstream
🔨 Feature Request
🛠️ Enhancement
🛠️ Enhancement
🛠️ Enhancement
❤️ Happy feedback
🔒 Security
🔍 Pending Validation
💆 UX
📝 WYSIWYG Editor
🌔 Out of scope
🔩 API Request
:octocat: Admin/Meta
🖌️ View Customization
❓ Question
🚀 Priority
🛡️ Blocked
🚚 Export System
♿ A11y
🔧 Maintenance
> Markdown Editor
pull-request
Mirrored from GitHub Pull Request
No Label
🐕 Support
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/BookStack#3930
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Alakadoo on GitHub (Jul 25, 2023).
Attempted Debugging
Searched GitHub Issues
Describe the Scenario
We have been using bookstack for some weeks now with ldap authentification enabled, everything was working fine.
Then we decided to rename the webiste, so I changed the name in the .env file, in the httpd conf file, in the web config panel page, did a new certificate to match the new name, and ran the php artisan bookstack:update-url.
But we are now unable to log in to existing accounts using ldap auth.
The ldap configuration is fine, if I create a new ldap user I can login to bookstack, but an existing user prior to renaming cannot log in after the rename, it shows the error "these credentials do not match our records", I checked the credentials multiple times they are fine.
I logged in with local admin account and deleted our registered ldap users thinking the accounts would recreate fine since I could login with new ldap account, but it did not work, same error. I checked in the users table of the bookstack database, the account are deleted.
The laravel.log, error.log and access.log show nothing related to the authentification error, turning on app_debug doesn't add any information to the error.
I'm out of ideas, I have trouble finding the relationship between the website rename and ldap authentification.
Does anyone have an idea to resolve this ?
Exact BookStack Version
23.06.2
Log Content
No response
PHP Version
8.0
Hosting Environment
Oracle 8
@ssddanbrown commented on GitHub (Jul 25, 2023):
I'm not familiar with that exact error, could you screenshot the exact error you see in this process? Just so I can understand better where it's coming from.
Really, there shouldn't be any kind of direct link between the app URL and LDAP auth functionality.
Did anything change on the LDAP/user side of things? For example, change of email domain for those users? or new LDAP system with same users imported?
@Alakadoo commented on GitHub (Jul 25, 2023):
Here is the error.
I enabled "LDAP_DUMP_USER_DETAILS" to get some more informations, and the json in return rightfully show all fields of my AD account, so there don't seem to be any communication problem between bookstack and AD.
Nothing changed in the AD side of things domain emails are the same, cn and samaccountname are the same too
It may be a coincidence I don't see any link either, yet I am unable to connect since. I have checked the ldap part of .env thinking maybe I've by mistake changed something, I've redone it from scratch but still nothing changed.
I also don't understand why a new AD user can connect, yet an existing user cannot, even after I deleted his account bookstack side and removed his entry in the users table of the database.
@Alakadoo commented on GitHub (Jul 25, 2023):
Nethermind, a colleague did not think it was useful to notify me that he had touched the ntlm connection delegation authorizations on AD.
Resolved, thank you for your help :)