{"record":{"id":"1e9815e0af86db81","repo":"sidorares/node-mysql2","slug":"unknown-ssl-profile-name","errorCode":null,"errorMessage":"Unknown SSL profile '${name}'","messagePattern":"Unknown SSL profile '(.+?)'","errorType":"validation","errorClass":"TypeError","httpStatus":null,"severity":"error","filePath":"lib/connection_config.js","lineNumber":270,"sourceCode":"\n    return defaultFlags;\n  }\n\n  static getCharsetNumber(charset) {\n    const num = Charsets[charset.toUpperCase()];\n    if (num === undefined) {\n      throw new TypeError(`Unknown charset '${charset}'`);\n    }\n    return num;\n  }\n\n  static getSSLProfile(name) {\n    if (!SSLProfiles) {\n      SSLProfiles = require('./constants/ssl_profiles.js');\n    }\n    const ssl = SSLProfiles[name];\n    if (ssl === undefined) {\n      throw new TypeError(`Unknown SSL profile '${name}'`);\n    }\n    return ssl;\n  }\n\n  static parseUrl(url) {\n    const parsedUrl = new URL(url);\n    const options = {\n      host: decodeURIComponent(parsedUrl.hostname),\n      port: parseInt(parsedUrl.port, 10),\n      database: decodeURIComponent(parsedUrl.pathname.slice(1)),\n      user: decodeURIComponent(parsedUrl.username),\n      password: decodeURIComponent(parsedUrl.password),\n    };\n    for (const [key, value] of parsedUrl.searchParams) {\n      if (key in options) {\n        continue;\n      }\n      try {","sourceCodeStart":252,"sourceCodeEnd":288,"githubUrl":"https://github.com/sidorares/node-mysql2/blob/8b1f829d3706404ab372cf97bd77ebcf86578d97/lib/connection_config.js#L252-L288","documentation":"ConnectionConfig.getSSLProfile (lib/connection_config.js:264-273) looks up the provided name in the bundled SSLProfiles map (lib/constants/ssl_profiles.js). If the name is not present it throws TypeError. The map ships only a curated set of well-known CA profiles (e.g. Amazon RDS names); arbitrary strings are rejected.","triggerScenarios":"Passing ssl: 'AmazonRDS' when that profile is not bundled or is differently named; passing a filename or alias expecting it to load a CA file; typo in a known profile name.","commonSituations":"Following an outdated tutorial referencing a profile name that was removed; assuming any string loads a CA bundle file (it does not — use an ssl object with ca: fs.readFileSync(...)).","solutions":["For custom CAs, pass an ssl object instead of a profile name: ssl: { ca: fs.readFileSync('/path/ca.pem') }.","Verify the bundled profile names in lib/constants/ssl_profiles.js before using a string.","For AWS RDS, download the region-specific CA bundle and pass it via the ssl.ca property."],"exampleFix":"// before\ncreateConnection({ ssl: 'my-rds-ca' }); // not a bundled profile\n\n// after\ncreateConnection({ ssl: { ca: fs.readFileSync('rds-ca.pem'), rejectUnauthorized: true } });","handlingStrategy":"validation","validationCode":"const fs = require('fs');\nfunction loadSsl(nameOrFile) {\n  if (typeof nameOrFile !== 'string') return nameOrFile;\n  // treat only known bundled profile names as strings; otherwise read a CA file\n  if (/\\.pem$/.test(nameOrFile)) return { ca: fs.readFileSync(nameOrFile), rejectUnauthorized: true };\n  return nameOrFile; // let mysql2 resolve the profile\n}","typeGuard":"const isSslProfileName = (v, profiles) => typeof v === 'string' && Object.prototype.hasOwnProperty.call(profiles, v);","tryCatchPattern":null,"preventionTips":["Prefer ssl objects with explicit ca/key/cert over profile-name strings.","Confirm a profile name exists in lib/constants/ssl_profiles.js before use."],"tags":["ssl","connection-config","validation","tls"],"backgroundTag":null,"analyzedSha":"8b1f829d3706404ab372cf97bd77ebcf86578d97","analyzedAt":"2026-08-11T02:54:28.964Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}