{"record":{"id":"2045163e13bdafaa","repo":"mongodb/node-mongodb-native","slug":"option-autoencryption-must-be-specified","errorCode":null,"errorMessage":"Option \"autoEncryption\" must be specified","messagePattern":"Option \"autoEncryption\" must be specified","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/encrypter.ts","lineNumber":22,"sourceCode":"import { MongoInvalidArgumentError, MongoMissingDependencyError } from './error';\nimport { MongoClient, type MongoClientOptions } from './mongo_client';\n\n/** @internal */\nexport interface EncrypterOptions {\n  autoEncryption: AutoEncryptionOptions;\n  maxPoolSize?: number;\n}\n\n/** @internal */\nexport class Encrypter {\n  private internalClient: MongoClient | null;\n  bypassAutoEncryption: boolean;\n  needsConnecting: boolean;\n  autoEncrypter: AutoEncrypter;\n\n  constructor(client: MongoClient, uri: string, options: MongoClientOptions) {\n    if (typeof options.autoEncryption !== 'object') {\n      throw new MongoInvalidArgumentError('Option \"autoEncryption\" must be specified');\n    }\n    // initialize to null, if we call getInternalClient, we may set this it is important to not overwrite those function calls.\n    this.internalClient = null;\n\n    this.bypassAutoEncryption = !!options.autoEncryption.bypassAutoEncryption;\n    this.needsConnecting = false;\n\n    if (options.maxPoolSize === 0 && options.autoEncryption.keyVaultClient == null) {\n      options.autoEncryption.keyVaultClient = client;\n    } else if (options.autoEncryption.keyVaultClient == null) {\n      options.autoEncryption.keyVaultClient = this.getInternalClient(client, uri, options);\n    }\n\n    if (this.bypassAutoEncryption) {\n      options.autoEncryption.metadataClient = undefined;\n    } else if (options.maxPoolSize === 0) {\n      options.autoEncryption.metadataClient = client;\n    } else {","sourceCodeStart":4,"sourceCodeEnd":40,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/encrypter.ts#L4-L40","documentation":"The internal Encrypter class (src/encrypter.ts:20) requires options.autoEncryption to be an object. It is constructed by MongoClient when autoEncryption is configured; if the value is present but not an object (or the Encrypter is invoked without it), this MongoInvalidArgumentError is thrown. Typically this reflects a malformed autoEncryption setting rather than a missing one (a missing setting would not construct an Encrypter at all).","triggerScenarios":"Passing autoEncryption: true, autoEncryption: null, or autoEncryption: 'enabled' to MongoClient options. Manually instantiating the internal Encrypter class (not supported) without an autoEncryption object.","commonSituations":"Treating autoEncryption as a boolean toggle instead of a config object. Typos or partial config where the autoEncryption key exists but is assigned a non-object value during refactoring.","solutions":["Provide autoEncryption as an object with at least a keyVaultNamespace and kmsProviders, e.g. autoEncryption: { keyVaultNamespace: 'encryption.__keyVault', kmsProviders: { ... } }.","Remove the autoEncryption key entirely if you did not intend to enable CSFLE.","Validate the shape of autoEncryption before constructing the MongoClient."],"exampleFix":"// before\nconst client = new MongoClient(uri, { autoEncryption: true });\n// after\nconst client = new MongoClient(uri, {\n  autoEncryption: {\n    keyVaultNamespace: 'encryption.__keyVault',\n    kmsProviders: { local: { key: localKey } }\n  }\n});","handlingStrategy":"validation","validationCode":"function validateAutoEncryption(opts) {\n  if (opts.autoEncryption != null && typeof opts.autoEncryption !== 'object') {\n    throw new TypeError('autoEncryption must be an object or omitted');\n  }\n  return opts;\n}\nconst client = new MongoClient(uri, validateAutoEncryption(opts));","typeGuard":"function isAutoEncryptionObject(v: unknown): v is Record<string, unknown> {\n  return v != null && typeof v === 'object' && !Array.isArray(v);\n}","tryCatchPattern":"try {\n  const client = new MongoClient(uri, opts);\n} catch (e) {\n  if (e instanceof MongoInvalidArgumentError && /autoEncryption/.test(e.message)) {\n    // fix autoEncryption shape\n  }\n  throw e;\n}","preventionTips":["Treat autoEncryption as a config object, never a boolean.","Define a TypeScript interface for your autoEncryption config to catch shape errors at compile time.","Centralize CSFLE config in one module to avoid divergent shapes."],"tags":["csfle","configuration","validation","synchronous"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}