Repository navigation
[Bug]: user_ldap Attempt for Paging? in Logging #31175
Description
Activity
- added0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmap
on Feb 14, 2022 Yes, still on
25.0.3. Not sure if this is important: the user "admin_user" is not on LDAP but a local one{ "reqId":"4yeOsXJoq1oWMFMpCPkx", "level":3, "time":"2023-01-23T15:54:19+00:00", "remoteAddr":"141.58.121.86", "user":"admin_user", "app":"user_ldap", "method":"POST", "url":"/apps/user_ldap/ajax/wizard.php", "message":"Attempt for Paging? ", "userAgent":"Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0", "version":"25.0.3.2", "data":{ "app":"user_ldap" }, "id":"63ceae53bc7ac" }Just to confirm I understand: the error is logged and those errors appear in the UI, but everything functions normally? 🤔
Can you provide the output of
occ ldap:show-config? Feel free to sensor out your domain/identifying info - just make sure any matching entries are the same/etc.EDIT: I also just noted you're using NGINX. Can you confirm the following two lines exist in your nginx config:
I suspect the telltale sign is that CLI test works, but not the web UI...
nextcloud-command commented
on Nov 11, 2023 on Nov 11, 2023 · Hidden as resolvedshow commentMore actions- addedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Nov 11, 2023 Sorry, forgot to answer.
-
I'm now on NC 27.1.3. The error messages about Attempt for Paging only show up rarely (last time2023-09-05) and while I was now doing these checks (but not sure at which point exactly).
-
I can confirm that the NGINX line exists.
-
The output of the command line check apparently got an update and the Web and Command line shows an error
root@asterix:~# sudo -u www-data /var/www/nextcloud/occ ldap:test-config s03 The configuration is valid and the bind passed, but a simple search on the base fails. Please check the server base setting.Just not sure to which field this relates... The
Base DN,Base User Tree,Base Group Tree, ...
(or it might come from the fact that we use LDAP Global Catalog?) -
The config is:
+-------------------------------+---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+ | Configuration | s03 | +-------------------------------+---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+ | hasMemberOfFilterSupport | 1 | | homeFolderNamingRule | | | lastJpegPhotoLookup | 0 | | ldapAgentName | CN=65574F13-674G-HF68-80F2-0050569B202E,OU=FuncUsers,OU=SIAM,DC=university,DC=de | | ldapAgentPassword | *** | | ldapAttributeAddress | | | ldapAttributeBiography | | | ldapAttributeFediverse | | | ldapAttributeHeadline | | | ldapAttributeOrganisation | | | ldapAttributePhone | | | ldapAttributeRole | | | ldapAttributeTwitter | | | ldapAttributeWebsite | | | ldapAttributesForGroupSearch | cn | | ldapAttributesForUserSearch | displayName;mail | | ldapBackgroundHost | | | ldapBackgroundPort | | | ldapBackupHost | | | ldapBackupPort | | | ldapBase | DC=university,DC=de | | ldapBaseGroups | DC=university,DC=de | | ldapBaseUsers | DC=university,DC=de;DC=stud,DC=university,DC=de | | ldapCacheTTL | 600 | | ldapConfigurationActive | 1 | | ldapConnectionTimeout | 15 | | ldapDefaultPPolicyDN | | | ldapDynamicGroupMemberURL | | | ldapEmailAttribute | mail | | ldapExperiencedAdmin | 1 | | ldapExpertUUIDGroupAttr | | | ldapExpertUUIDUserAttr | | | ldapExpertUsernameAttr | | | ldapExtStorageHomeAttribute | | | ldapGidNumber | gidNumber | | ldapGroupDisplayName | cn | | ldapGroupFilter | (&(objectClass=group)(CN=ABC-*)(!(|(CN=ABC-CIFS*)(CN=ABC-OU*)(CN=ABC-DNS*)(CN=ABC-Administratoren)))) | | ldapGroupFilterGroups | | | ldapGroupFilterMode | 0 | | ldapGroupFilterObjectclass | | | ldapGroupMemberAssocAttr | member | | ldapHost | ldaps://adserv17.university.de | | ldapIgnoreNamingRules | | | ldapLoginFilter | (&(objectClass=InetOrgPerson)(memberof:1.2.840.113556.1.4.1941:=CN=ABC-service-nextcloud,OU=ABC-services,OU=ABC,OU=Fak-42,DC=university,DC=de)(|(sAMAccountName=%uid)(mail=%uid))) | | ldapLoginFilterAttributes | | | ldapLoginFilterEmail | 0 | | ldapLoginFilterMode | 0 | | ldapLoginFilterUsername | 1 | | ldapMatchingRuleInChainState | available | | ldapNestedGroups | 1 | | ldapOverrideMainServer | | | ldapPagingSize | 0 | | ldapPort | 3269 | | ldapQuotaAttribute | | | ldapQuotaDefault | | | ldapTLS | 0 | | ldapUserAvatarRule | none | | ldapUserDisplayName | displayname | | ldapUserDisplayName2 | mail | | ldapUserFilter | (&(objectclass=InetOrgPerson)(memberof:1.2.840.113556.1.4.1941:=CN=ABC-service-nextcloud,OU=ABC-services,OU=ABC,OU=Fak-42,DC=university,DC=de)) | | ldapUserFilterGroups | Domänen-Admins | | ldapUserFilterMode | 0 | | ldapUserFilterObjectclass | inetOrgPerson | | ldapUuidGroupAttribute | auto | | ldapUuidUserAttribute | auto | | turnOffCertCheck | 0 | | turnOnPasswordChange | 0 | | useMemberOfToDetectMembership | 1 | +-------------------------------+---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+
-
- removedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Nov 16, 2023 I have the same issue, but running on apache2. Described it in the nextcloud forums, not solved (yet).
https://help.nextcloud.com/t/attempt-for-paging-bad-search-filter/185970
still present in 29.0.3, seems to be related if LDAP - server has a inactivity timeout set.
- addedneeds reviewNeeds review to determine if still applicable or covered by other IssuesNeeds review to determine if still applicable or covered by other Issues
on Sep 6, 2024 Also in v30.0.2
[user_ldap] Error: Attempt for Paging? GET /settings/ajax/checksetup from XX.XXX.XX.XXX by admin.user at 20.11.2024, 21:15:47Raw entry:
{"reqId":"W4RIktcS5Z7xYHAkoqU3","level":3,"time":"2024-11-20T20:15:47+00:00","remoteAddr":"XX.XXX.XX.XXX","user":"admin.user","app":"user_ldap","method":"GET","url":"/settings/ajax/checksetup","message":"Attempt for Paging? ","userAgent":"Mozilla/5.0 (X11; Linux x86_64; rv:131.0) Gecko/20100101 Firefox/131.0","version":"30.0.2.2","data":{"app":"user_ldap"},"id":"673e4438c5b75"}I think it happens when accessing the LDAP config page.
This is also happening on 31.0.5, with apache2:
{"reqId":"3ABY0lfSCORBcODRiZTt","level":3,"time":"2025-06-10T15:55:52-03:00","remoteAddr":"REDACTED","user":"super-usuario","app":"user_ldap","method":"POST","url":"/index.php/apps/user_ldap/ajax/wizard.php","message":"Attempt for Paging? 1","userAgent":"Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0","version":"31.0.5.1","data":{"app":"user_ldap"}}This happens on its own and floods the logs, but one way to force it is to run "Test Base DN" inside config panel. My Base DN is the following:
dc=udelar,dc=edu,dc=uyStill on 33.
It says bad filter in /nextcloud/apps/user_ldap/lib/LDAP.php#285Which is part of this block :
/** * @param array $arguments * @return mixed */ protected function invokeLDAPMethod(string $func, ...$arguments) { $func = 'ldap_' . $func; if (function_exists($func)) { $this->preFunctionCall($func, $arguments); $result = call_user_func_array($func, $arguments); if ($this->isResultFalse($func, $result)) { $this->postFunctionCall($func); } if ($this->dataCollector !== null) { $this->dataCollector->stopLastLdapRequest(); } return $result; } return null; }Still on 34.
The line number changed for LDAP.php#304 but when we look at the code :/**
* @PARAM array $arguments
* @return mixed
*/
protected function invokeLDAPMethod(string $func, ...$arguments) {
$func = 'ldap_' . $func;
if (function_exists($func)) {
$this->preFunctionCall($func, $arguments);
$result = call_user_func_array($func, $arguments);
if ($this->isResultFalse($func, $result)) {
$this->postFunctionCall($func);
}
if ($this->dataCollector !== null) {
$this->dataCollector->stopLastLdapRequest();
}
return $result;
}
return null;
}The line just moved.
Bug description
In the admin logging I get the Error "Attempt for Paging?" from the
user_ldapapp.Not sure if related, but the LDAP/AD integration interface says
Configuration incorrectand thatThe Base DN appears to be wrongbut when checking on command line everything appears to be correctroot@machine01:/var/www/nextcloud# sudo -u www-data ./occ ldap:test-config s03 The configuration is valid and the connection could be established!Using google I stumbled into this owncloud/user_ldap#423 which seems related.
Steps to reproduce
Expected behavior
Installation method
Manual installation
Operating system
Debian/Ubuntu
PHP engine version
PHP 7.4
Web server
Nginx
Database engine version
MariaDB
Is this bug present after an update or on a fresh install?
Updated to a major version (ex. 22.2.3 to 23.0.1)
Are you using the Nextcloud Server Encryption module?
Encryption is Disabled
What user-backends are you using?
Configuration report
{ "system": { "instanceid": "***REMOVED SENSITIVE VALUE***", "passwordsalt": "***REMOVED SENSITIVE VALUE***", "secret": "***REMOVED SENSITIVE VALUE***", "trusted_domains": [ "nc.top.secret.de", "nc.topp.secret.de" ], "datadirectory": "***REMOVED SENSITIVE VALUE***", "dbtype": "mysql", "version": "22.2.3.0", "overwrite.cli.url": "https:\/\/nc.top.secret.de", "dbname": "***REMOVED SENSITIVE VALUE***", "dbhost": "***REMOVED SENSITIVE VALUE***", "dbport": "", "dbtableprefix": "oc_", "dbuser": "***REMOVED SENSITIVE VALUE***", "dbpassword": "***REMOVED SENSITIVE VALUE***", "installed": true, "mysql.utf8mb4": true, "maintenance": false, "session_lifetime": 604800, "session_keepalive": true, "mail_smtpmode": "smtp", "mail_sendmailmode": "smtp", "mail_domain": "***REMOVED SENSITIVE VALUE***", "mail_from_address": "***REMOVED SENSITIVE VALUE***", "mail_smtphost": "***REMOVED SENSITIVE VALUE***", "mail_smtpport": "25", "default_language": "de_DE", "default_locale": "de", "default_phone_region": "DE", "skeletondirectory": "", "loglevel": 2, "updater.release.channel": "stable", "app_install_overwrite": [ "drawio" ], "mail_smtpsecure": "tls", "ldapIgnoreNamingRules": false, "ldapProviderFactory": "OCA\\User_LDAP\\LDAPProviderFactory", "memcache.local": "\\OC\\Memcache\\APCu", "memcache.distributed": "\\OC\\Memcache\\Redis", "memcache.locking": "\\OC\\Memcache\\Redis", "redis": { "host": "***REMOVED SENSITIVE VALUE***", "port": 0, "password": "***REMOVED SENSITIVE VALUE***" } } }List of activated Apps
Nextcloud Signing status
Nextcloud Logs
{"reqId":"xM6hlC9vjtmWFGEx5Lpo","level":3,"time":"2022-02-14T16:18:33+00:00","remoteAddr":"123.456.789.123","user":"admin.sonn","app":"user_ldap","method":"POST","url":"/apps/user_ldap/ajax/wizard.php","message":"Attempt for Paging? ","userAgent":"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:96.0) Gecko/20100101 Firefox/96.0","version":"22.2.3.0","id":"620a80d9cb9ae"}Additional info
We are using Global Catalog (port 3269)