{"record":{"id":"139c04aa29d566f7","repo":"mongodb/node-mongodb-native","slug":"expected-result-of-decryption-to-be-deserialized-b","errorCode":null,"errorMessage":"Expected result of decryption to be deserialized BSON object","messagePattern":"Expected result of decryption to be deserialized BSON object","errorType":"exception","errorClass":"MongoRuntimeError","httpStatus":null,"severity":"error","filePath":"src/utils.ts","lineNumber":1358,"sourceCode":" * Recurse through the (identically-shaped) `decrypted` and `original`\n * objects and attach a `decryptedKeys` property on each sub-object that\n * contained encrypted fields. Because we only call this on BSON responses,\n * we do not need to worry about circular references.\n *\n * @internal\n */\nexport function decorateDecryptionResult(\n  decrypted: Document & { [kDecoratedKeys]?: Array<string> },\n  original: Document,\n  isTopLevelDecorateCall = true\n): void {\n  if (isTopLevelDecorateCall) {\n    // The original value could have been either a JS object or a BSON buffer\n    if (ByteUtils.isUint8Array(original)) {\n      original = deserialize(original);\n    }\n    if (ByteUtils.isUint8Array(decrypted)) {\n      throw new MongoRuntimeError('Expected result of decryption to be deserialized BSON object');\n    }\n  }\n\n  if (!decrypted || typeof decrypted !== 'object') return;\n  for (const k of Object.keys(decrypted)) {\n    const originalValue = original[k];\n\n    // An object was decrypted by libmongocrypt if and only if it was\n    // a BSON Binary object with subtype 6.\n    if (originalValue && originalValue._bsontype === 'Binary' && originalValue.sub_type === 6) {\n      if (!decrypted[kDecoratedKeys]) {\n        Object.defineProperty(decrypted, kDecoratedKeys, {\n          value: [],\n          configurable: true,\n          enumerable: false,\n          writable: false\n        });\n      }","sourceCodeStart":1340,"sourceCodeEnd":1376,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/utils.ts#L1340-L1376","documentation":"Thrown by decorateDecryptionResult() when the decrypted value passed in is still a Uint8Array (raw bytes) rather than a deserialized BSON object. In CSFLE/Queryable Encryption flows the driver expects the encryption library to return a deserialized document; receiving raw bytes indicates the decryption layer did not deserialize correctly. Raised as MongoRuntimeError.","triggerScenarios":"Internal CSFLE auto-decryption path where mongodb-client-encryption returns a Uint8Array instead of an object for the decrypted command response. Not triggered by direct user API misuse; indicates an incompatibility between the driver and the encryption native bindings, or a corrupted response.","commonSituations":"Version mismatch between the mongodb driver and mongodb-client-encryption (libmongocrypt bindings). Corrupt or unexpected server responses when CSFLE is enabled. Seen during driver/encryption-library upgrades if peer dependencies are not updated together.","solutions":["Ensure the mongodb driver and mongodb-client-encryption versions are compatible per the driver's changelog/peer-dep matrix.","Reinstall dependencies cleanly (rm -rf node_modules && npm install) to fix native binding build issues.","If the error persists, capture the command/response context and file a bug with driver and encryption-library versions."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await client.db('enc').collection('patients').findOne(filter);\n} catch (e) {\n  if (e instanceof MongoRuntimeError && /Expected result of decryption/.test(e.message)) {\n    // align driver and mongodb-client-encryption versions; reinstall native bindings\n  } else throw e;\n}","preventionTips":["Keep the mongodb driver and mongodb-client-encryption on mutually compatible versions.","Rebuild native bindings after Node.js version upgrades (rm -rf node_modules && npm install).","Pin CSFLE-related dependencies explicitly to avoid silent peer-dep drift."],"tags":["csfle","encryption","internal","bson"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}