Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Nextcloud
  3. LDAP usergroups reset?

LDAP usergroups reset?

Scheduled Pinned Locked Moved Solved Nextcloud
8 Posts 3 Posters 1.4k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • David 0D Offline
    David 0D Offline
    David 0
    wrote on last edited by
    #1

    Hi,

    I've installed the latest Nextcloud release and ever since I get regular emails (1 per hour) that some accounts were deleted as administrators from certain groups.
    After updating the nextcloud app, I updated cloudron itself to the latest version (I forgot on this particular server to do so earlier), maybe that should resolve my problem. It did not.

    Strangely, in Nextcloud, everything showed up as it should (and worked). So I dug deeper: Here's one error from the Nextcloud Log that seems to point at this issue:

    [index] Fehler: An exception occurred while executing a query: SQLSTATE[23505]: Unique violation: 7 ERROR:  duplicate key value violates unique constraint "user_ldap_membership_unique"
    DETAIL:  Key (groupid, userid)=(cl-komm-kommunikation, davidlohner) already exists.
    

    I remember having trouble setting up a proper sync of the Cloudron groups into Nextcloud when initially getting everything running. Maybe some of my modifications in the LDAP-config of Nextcloud do backfire now?

    In Nextcloud in the LDAP/AD-Settings, I have

    • ou=users,dc=cloudron next to the Base-DN Settings and
    • (objectclass=group) in the "groups"-tab.

    Deleting and re-adding the latter setting in the groups tab seemed to solve this issue (so for a brief moment, all users had no group assigned to them in Nextcloud), at least the emails stopped.

    I really hope this was just a hiccup.

    1 Reply Last reply
    0
    • nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote on last edited by
      #2

      At least on Cloudron side nothing changed in that area in the latest release and also the Nextcloud LDAP config was untouched. So maybe if this comes back, it may be a regression in Nextcloud and/or the LDAP plugin there.

      1 Reply Last reply
      0
      • David 0D Offline
        David 0D Offline
        David 0
        wrote on last edited by David 0
        #3

        Oh no, the emails did not stop![1] 😑
        thanks for your reply, though.
        I'm going to dive deeper into the logs and the Nextcloud forums. Maybe (hopefully!) I'll find some hints what's going on over there.

        The Nextcloud Activity-App tells me that around every hour or so "an administrator deleted me from a group". Around 5-10 minutes later, my own account re-adds me to the same groups.

        [1]: I've disabled e-mail notifications.

        1 Reply Last reply
        0
        • David 0D Offline
          David 0D Offline
          David 0
          wrote on last edited by
          #4

          Just wanted to share an update: I guess the "extended permissions" in the group folder app/settings were responsible for my troubles.

          Everything works fine now. (this topic can be marked as "solved")

          1 Reply Last reply
          1
          • nebulonN Offline
            nebulonN Offline
            nebulon
            Staff
            wrote on last edited by
            #5

            Thanks for sharing the root cause.

            1 Reply Last reply
            0
            • nebulonN nebulon marked this topic as a question on
            • nebulonN nebulon has marked this topic as solved on
            • David 0D David 0 has marked this topic as unsolved on
            • David 0D Offline
              David 0D Offline
              David 0
              wrote on last edited by
              #6

              sigh here we are again.

              Tonight, I received multiple emails as described in the first post. Strangely, I could not identify, why some users received them multiple times, others just once.

              I could not find any connection looking at the timestamps of those emails (01:10am, 3:20am, 5:30am, all mentioning some events exactly 5 minutes prior) and the log files of Cloudron or the Nextcloud app.

              Is there an "official" way to sync Cloudron groups into Nextcloud? I've done that with some other tutorials I found when initially configuring my Nextcloud. Here are my current settings. Maybe there is something wrong with them?

              Server Settings
              LDAP_01_Server.png

              User Settings
              LDAP_02_User.png

              Attributes Settings
              LDAP_03_Attributes.png

              Group Settings
              LDAP_04_Groups.png

              1 Reply Last reply
              0
              • nebulonN Offline
                nebulonN Offline
                nebulon
                Staff
                wrote on last edited by
                #7

                I think I got down to the root problem of this. The change is https://git.cloudron.io/cloudron/nextcloud-app/-/commit/56e32573b80cb9cd5dd45d16a977f8ecf395384c and the new package is out.

                @David-0 let us know if this solves it for you as well.

                1 Reply Last reply
                0
                • avatar1024A Offline
                  avatar1024A Offline
                  avatar1024
                  wrote on last edited by
                  #8

                  @nebulon thank you for this! I had this same issue for months and your fix seems to work. Something must have changed with NC28 as other (non cloudron) users have experienced and reported this in NC github. In fact I hadn't even thought of reporting it here as I thought it was not cloudron related. I wonders if what you did to the NC cloudron package could be helpful to others...?

                  1 Reply Last reply
                  0
                  • girishG girish has marked this topic as solved on
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • Bookmarks
                  • Search