{"record":{"id":"374f56697d72b8cd","repo":"mongodb/node-mongodb-native","slug":"authcontext-must-contain-a-valid-nonce-property","errorCode":null,"errorMessage":"AuthContext must contain a valid nonce property","messagePattern":"AuthContext must contain a valid nonce property","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/scram.ts","lineNumber":106,"sourceCode":"  // Since the username is not sasl-prep-d, we need to do this here.\n  return {\n    saslStart: 1,\n    mechanism,\n    payload: new Binary(\n      ByteUtils.concat([ByteUtils.fromUTF8('n,,'), clientFirstMessageBare(username, nonce)])\n    ),\n    autoAuthorize: 1,\n    options: { skipEmptyExchange: true }\n  };\n}\n\nasync function executeScram(cryptoMethod: CryptoMethod, authContext: AuthContext): Promise<void> {\n  const { connection, credentials } = authContext;\n  if (!credentials) {\n    throw new MongoMissingCredentialsError('AuthContext must provide credentials.');\n  }\n  if (!authContext.nonce) {\n    throw new MongoInvalidArgumentError('AuthContext must contain a valid nonce property');\n  }\n  const nonce = authContext.nonce;\n  const db = credentials.source;\n\n  const saslStartCmd = makeFirstMessage(cryptoMethod, credentials, nonce);\n  const response = await connection.command(ns(`${db}.$cmd`), saslStartCmd, undefined);\n  await continueScramConversation(cryptoMethod, response, authContext);\n}\n\nasync function continueScramConversation(\n  cryptoMethod: CryptoMethod,\n  response: Document,\n  authContext: AuthContext\n): Promise<void> {\n  const connection = authContext.connection;\n  const credentials = authContext.credentials;\n  if (!credentials) {\n    throw new MongoMissingCredentialsError('AuthContext must provide credentials.');","sourceCodeStart":88,"sourceCodeEnd":124,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/scram.ts#L88-L124","documentation":"Thrown by executeScram (scram.ts:106) when authContext.nonce is unset. The nonce is generated during prepare() (scram.ts:35-37); reaching this throw means auth() was invoked without prepare() having populated the nonce first. Raised as MongoInvalidArgumentError. This is an internal ordering invariant: normal handshakes always run prepare before auth.","triggerScenarios":"A code path that invokes ScramSHA.auth() directly without first calling ScramSHA.prepare(), or a driver regression where the handshake skipped the prepare step. Not reachable through the standard MongoClient connect flow.","commonSituations":"Forking or unit-testing the SCRAM provider by calling auth() in isolation. A driver bug where speculative auth and the non-speculative path interact to skip prepare(). Re-authentication after connection pool reset losing the nonce.","solutions":["If reached via the public API, file a driver bug with a reproduction","When invoking the internal provider directly, call prepare() before auth() so the nonce is set","Upgrade the driver in case the ordering bug is already fixed"],"exampleFix":"// before (internal misuse)\nawait provider.auth(authContext); // nonce never set\n\n// after\nawait provider.prepare(handshakeDoc, authContext);\nawait provider.auth(authContext);","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (err) {\n  if (err instanceof MongoInvalidArgumentError && /nonce/.test(err.message)) {\n    // internal ordering bug: report to driver maintainers with a reproduction\n    reportDriverBug(err);\n  }\n  throw err;\n}","preventionTips":["Do not call the internal SCRAM provider methods out of order","If you fork auth providers, always run prepare() before auth()","Pin a stable driver version and upgrade deliberately to pick up handshake fixes"],"tags":["scram","internal","invariant","authentication"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}