{"record":{"id":"03516672c8eb9e81","repo":"mongodb/node-mongodb-native","slug":"auth-mechanism-property-allowed-hosts-is-not-allow","errorCode":null,"errorMessage":"Auth mechanism property ALLOWED_HOSTS is not allowed in the connection string.","messagePattern":"Auth mechanism property ALLOWED_HOSTS is not allowed in the connection string\\.","errorType":"exception","errorClass":"MongoParseError","httpStatus":null,"severity":"error","filePath":"src/connection_string.ts","lineNumber":322,"sourceCode":"  }\n\n  const objectOptions = new CaseInsensitiveMap<unknown>(\n    Object.entries(options).filter(([, v]) => v != null)\n  );\n\n  // Validate options that can only be provided by one of uri or object\n\n  if (urlOptions.has('serverApi')) {\n    throw new MongoParseError(\n      'URI cannot contain `serverApi`, it can only be passed to the client'\n    );\n  }\n\n  const uriMechanismProperties = urlOptions.get('authMechanismProperties');\n  if (uriMechanismProperties) {\n    for (const property of uriMechanismProperties) {\n      if (/(^|,)ALLOWED_HOSTS:/.test(property as string)) {\n        throw new MongoParseError(\n          'Auth mechanism property ALLOWED_HOSTS is not allowed in the connection string.'\n        );\n      }\n    }\n  }\n\n  if (objectOptions.has('loadBalanced')) {\n    throw new MongoParseError('loadBalanced is only a valid option in the URI');\n  }\n\n  // All option collection\n\n  const allProvidedOptions = new CaseInsensitiveMap<unknown[]>();\n\n  const allProvidedKeys = new Set<string>([...urlOptions.keys(), ...objectOptions.keys()]);\n\n  for (const key of allProvidedKeys) {\n    const values = [];","sourceCodeStart":304,"sourceCodeEnd":340,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/connection_string.ts#L304-L340","documentation":"ALLOWED_HOSTS is an OIDC auth-mechanism property that controls which hosts the driver may redirect to during OIDC token exchange. For security it must be supplied programmatically (via the options object), never via the connection string, so an attacker-controlled URI cannot redirect credentials. The driver scans authMechanismProperties values in the URI and rejects any containing 'ALLOWED_HOSTS:'.","triggerScenarios":"A URI containing 'authMechanismProperties=ALLOWED_HOSTS:example.com' (or any comma-separated variant matching the regex). Checked after urlOptions are collected.","commonSituations":"Copy-pasting OIDC config into the connection string for convenience, or older examples that predate this restriction.","solutions":["Remove ALLOWED_HOSTS from the URI authMechanismProperties.","Configure authMechanismProperties (including ALLOWED_HOSTS) via the options object instead."],"exampleFix":"// before\nnew MongoClient('mongodb://h/db?authMechanism=MONGODB-OIDC&authMechanismProperties=ALLOWED_HOSTS:example.com');\n// after\nnew MongoClient('mongodb://h/db?authMechanism=MONGODB-OIDC', { authMechanismProperties: { ALLOWED_HOSTS: 'example.com' } });","handlingStrategy":"validation","validationCode":"function assertNoAllowedHostsInUri(uri: string) {\n  const q = uri.split('?')[1] ?? '';\n  if (/authMechanismProperties=[^&]*ALLOWED_HOSTS:/i.test(q)) {\n    throw new Error('ALLOWED_HOSTS must be set via options.authMechanismProperties, not the URI');\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Treat the connection string as untrusted for security-sensitive options.","Configure OIDC authMechanismProperties programmatically."],"tags":["connection-string","oidc","auth","security","validation"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}