{"record":{"id":"3f403428c70655de","repo":"FasterXML/jackson-databind","slug":"cannot-use-includeas-of-for-default-typing","errorCode":null,"errorMessage":"Cannot use includeAs of {} for Default Typing","messagePattern":"Cannot use includeAs of (.+?) for Default Typing","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"src/main/java/tools/jackson/databind/cfg/MapperBuilder.java","lineNumber":1785,"sourceCode":"     * and attempts of do so will throw an {@link IllegalArgumentException} to make\n     * this limitation explicit.\n     *<p>\n     * NOTE: choice of {@link PolymorphicTypeValidator} to configure is of\n     * crucial importance to security when deserializing untrusted content:\n     * this because allowing deserializing of any type can lead to malicious\n     * attacks using \"deserialization gadgets\". Implementations should use\n     * allow-listing to specify acceptable types unless source of content\n     * is fully trusted to only send safe types.\n     *\n     * @param applicability Defines kinds of types for which additional type information\n     *    is added; see {@link DefaultTyping} for more information.\n     */\n    public B activateDefaultTyping(PolymorphicTypeValidator subtypeValidator,\n            DefaultTyping applicability, JsonTypeInfo.As includeAs)\n    {\n        // Use if \"As.EXTERNAL_PROPERTY\" will not work, check to ensure no attempts made\n        if (includeAs == JsonTypeInfo.As.EXTERNAL_PROPERTY) {\n            throw new IllegalArgumentException(\"Cannot use includeAs of \"+includeAs+\" for Default Typing\");\n        }\n        return setDefaultTyping(_defaultDefaultTypingResolver(subtypeValidator,\n                applicability, includeAs));\n    }\n\n    /**\n     * Method for enabling automatic inclusion of type information -- needed\n     * for proper deserialization of polymorphic types (unless types\n     * have been annotated with {@link com.fasterxml.jackson.annotation.JsonTypeInfo}) --\n     * using \"As.PROPERTY\" inclusion mechanism and specified property name\n     * to use for inclusion (default being \"@class\" since default type information\n     * always uses class name as type identifier)\n     *<p>\n     * NOTE: choice of {@link PolymorphicTypeValidator} to configure is of\n     * crucial importance to security when deserializing untrusted content:\n     * this because allowing deserializing of any type can lead to malicious\n     * attacks using \"deserialization gadgets\". Implementations should use\n     * allow-listing to specify acceptable types unless source of content","sourceCodeStart":1767,"sourceCodeEnd":1803,"githubUrl":"https://github.com/FasterXML/jackson-databind/blob/87876ca5c0569b4933aec2d30d6225e4b9ba3a43/src/main/java/tools/jackson/databind/cfg/MapperBuilder.java#L1767-L1803","documentation":"Thrown by MapperBuilder.activateDefaultTyping(PolymorphicTypeValidator, DefaultTyping, JsonTypeInfo.As) when includeAs is JsonTypeInfo.As.EXTERNAL_PROPERTY. Default Typing cannot use external-property inclusion because the type metadata must be embedded alongside values globally; Jackson explicitly rejects this combination to make the limitation obvious.","triggerScenarios":"Calling activateDefaultTyping(validator, applicability, JsonTypeInfo.As.EXTERNAL_PROPERTY) on a MapperBuilder.","commonSituations":"Migrating from per-type @JsonTypeInfo(use=Id.CLASS, include=As.EXTERNAL_PROPERTY) to global Default Typing and reusing the same As enum; copy-paste of an include-mode constant; misreading the docs about which As values are valid for default typing.","solutions":["Use one of the supported inclusion styles: JsonTypeInfo.As.WRAPPER_ARRAY (default), WRAPPER_OBJECT, or PROPERTY.","If you genuinely need EXTERNAL_PROPERTY, configure it per-type via @JsonTypeInfo on the target type instead of global Default Typing.","Use activateDefaultTyping(validator, applicability) (two-arg) to get the safe default WRAPPER_ARRAY."],"exampleFix":"// before\nbuilder.activateDefaultTyping(validator,\n    DefaultTyping.NON_FINAL,\n    JsonTypeInfo.As.EXTERNAL_PROPERTY);\n\n// after\nbuilder.activateDefaultTyping(validator,\n    DefaultTyping.NON_FINAL,\n    JsonTypeInfo.As.WRAPPER_ARRAY);","handlingStrategy":"validation","validationCode":"JsonTypeInfo.As includeAs = JsonTypeInfo.As.EXTERNAL_PROPERTY; // from config\nif (includeAs == JsonTypeInfo.As.EXTERNAL_PROPERTY) {\n    includeAs = JsonTypeInfo.As.WRAPPER_ARRAY; // or reject\n}\nbuilder.activateDefaultTyping(validator, applicability, includeAs);","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Remember Default Typing supports only WRAPPER_ARRAY, WRAPPER_OBJECT, PROPERTY.","Use the two-arg activateDefaultTyping to get the safe default.","Reserve EXTERNAL_PROPERTY for per-type @JsonTypeInfo, not global default typing."],"tags":["jackson","polymorphism","default-typing","config","builder","security"],"backgroundTag":null,"analyzedSha":"87876ca5c0569b4933aec2d30d6225e4b9ba3a43","analyzedAt":"2026-08-11T12:55:24.033Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}