FasterXML/jackson-databind · error · IllegalArgumentException
Cannot use includeAs of
Error message
Cannot use includeAs of {} for Default Typing What it means
Thrown by MapperBuilder.activateDefaultTyping(PolymorphicTypeValidator, DefaultTyping, JsonTypeInfo.As) when includeAs is JsonTypeInfo.As.EXTERNAL_PROPERTY. Default Typing cannot use external-property inclusion because the type metadata must be embedded alongside values globally; Jackson explicitly rejects this combination to make the limitation obvious.
Solutions
- Use one of the supported inclusion styles: JsonTypeInfo.As.WRAPPER_ARRAY (default), WRAPPER_OBJECT, or PROPERTY.
- If you genuinely need EXTERNAL_PROPERTY, configure it per-type via @JsonTypeInfo on the target type instead of global Default Typing.
- Use activateDefaultTyping(validator, applicability) (two-arg) to get the safe default WRAPPER_ARRAY.
Example fix
// before
builder.activateDefaultTyping(validator,
DefaultTyping.NON_FINAL,
JsonTypeInfo.As.EXTERNAL_PROPERTY);
// after
builder.activateDefaultTyping(validator,
DefaultTyping.NON_FINAL,
JsonTypeInfo.As.WRAPPER_ARRAY); Defensive patterns
Strategy: validation
Validate before calling
JsonTypeInfo.As includeAs = JsonTypeInfo.As.EXTERNAL_PROPERTY; // from config
if (includeAs == JsonTypeInfo.As.EXTERNAL_PROPERTY) {
includeAs = JsonTypeInfo.As.WRAPPER_ARRAY; // or reject
}
builder.activateDefaultTyping(validator, applicability, includeAs); Prevention
- Remember Default Typing supports only WRAPPER_ARRAY, WRAPPER_OBJECT, PROPERTY.
- Use the two-arg activateDefaultTyping to get the safe default.
- Reserve EXTERNAL_PROPERTY for per-type @JsonTypeInfo, not global default typing.
When it happens
Trigger: Calling activateDefaultTyping(validator, applicability, JsonTypeInfo.As.EXTERNAL_PROPERTY) on a MapperBuilder.
Common situations: Migrating from per-type @JsonTypeInfo(use=Id.CLASS, include=As.EXTERNAL_PROPERTY) to global Default Typing and reusing the same As enum; copy-paste of an include-mode constant; misreading the docs about which As values are valid for default typing.
Related errors
- Cannot pass null modifier
- Cannot pass null resolver
- Cannot pass null resolver
- Module ( ) without defined name
- Module ( ) without defined version
AI-assisted analysis of FasterXML/jackson-databind@87876ca5c0 (2026-08-11).
Data as JSON: /api/errors/3f403428c70655de.
Report an issue: GitHub.
Appendix: source
Thrown at src/main/java/tools/jackson/databind/cfg/MapperBuilder.java:1785
* and attempts of do so will throw an {@link IllegalArgumentException} to make
* this limitation explicit.
*<p>
* NOTE: choice of {@link PolymorphicTypeValidator} to configure is of
* crucial importance to security when deserializing untrusted content:
* this because allowing deserializing of any type can lead to malicious
* attacks using "deserialization gadgets". Implementations should use
* allow-listing to specify acceptable types unless source of content
* is fully trusted to only send safe types.
*
* @param applicability Defines kinds of types for which additional type information
* is added; see {@link DefaultTyping} for more information.
*/
public B activateDefaultTyping(PolymorphicTypeValidator subtypeValidator,
DefaultTyping applicability, JsonTypeInfo.As includeAs)
{
// Use if "As.EXTERNAL_PROPERTY" will not work, check to ensure no attempts made
if (includeAs == JsonTypeInfo.As.EXTERNAL_PROPERTY) {
throw new IllegalArgumentException("Cannot use includeAs of "+includeAs+" for Default Typing");
}
return setDefaultTyping(_defaultDefaultTypingResolver(subtypeValidator,
applicability, includeAs));
}
/**
* Method for enabling automatic inclusion of type information -- needed
* for proper deserialization of polymorphic types (unless types
* have been annotated with {@link com.fasterxml.jackson.annotation.JsonTypeInfo}) --
* using "As.PROPERTY" inclusion mechanism and specified property name
* to use for inclusion (default being "@class" since default type information
* always uses class name as type identifier)
*<p>
* NOTE: choice of {@link PolymorphicTypeValidator} to configure is of
* crucial importance to security when deserializing untrusted content:
* this because allowing deserializing of any type can lead to malicious
* attacks using "deserialization gadgets". Implementations should use
* allow-listing to specify acceptable types unless source of contentView on GitHub (pinned to 87876ca5c0)