{"record":{"id":"4a703ca01f8f6687","repo":"go-sql-driver/mysql","slug":"invalid-value-for-tls-config-name-v","errorCode":null,"errorMessage":"invalid value for TLS config name: %v","messagePattern":"invalid value for TLS config name: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"dsn.go","lineNumber":661,"sourceCode":"\t\t\tif err != nil {\n\t\t\t\treturn\n\t\t\t}\n\n\t\t// TLS-Encryption\n\t\tcase \"tls\":\n\t\t\tboolValue, isBool := readBool(value)\n\t\t\tif isBool {\n\t\t\t\tif boolValue {\n\t\t\t\t\tcfg.TLSConfig = \"true\"\n\t\t\t\t} else {\n\t\t\t\t\tcfg.TLSConfig = \"false\"\n\t\t\t\t}\n\t\t\t} else if vl := strings.ToLower(value); vl == \"skip-verify\" || vl == \"preferred\" {\n\t\t\t\tcfg.TLSConfig = vl\n\t\t\t} else {\n\t\t\t\tname, err := url.QueryUnescape(value)\n\t\t\t\tif err != nil {\n\t\t\t\t\treturn fmt.Errorf(\"invalid value for TLS config name: %v\", err)\n\t\t\t\t}\n\t\t\t\tcfg.TLSConfig = name\n\t\t\t}\n\n\t\t// I/O write Timeout\n\t\tcase \"writeTimeout\":\n\t\t\tcfg.WriteTimeout, err = time.ParseDuration(value)\n\t\t\tif err != nil {\n\t\t\t\treturn\n\t\t\t}\n\t\tcase \"maxAllowedPacket\":\n\t\t\tcfg.MaxAllowedPacket, err = strconv.Atoi(value)\n\t\t\tif err != nil {\n\t\t\t\treturn\n\t\t\t}\n\n\t\t// Connection attributes\n\t\tcase \"connectionAttributes\":","sourceCodeStart":643,"sourceCodeEnd":679,"githubUrl":"https://github.com/go-sql-driver/mysql/blob/03d76c7e07908e255ce62d126d07ede3f2365d86/dsn.go#L643-L679","documentation":"The 'tls' DSN parameter accepts the literals true/false/skip-verify/preferred or the name of a TLS config registered via mysql.RegisterTLSConfig. If the value is none of those literals, the driver treats it as a config name and url.QueryUnescape's it; a bad percent-escape yields this error.","triggerScenarios":"A DSN like '?tls=%ZZ' where the value is not a recognized literal and contains a malformed percent-escape. Plain bad references like 'tls=custom' (a valid name) do not trigger this; only decode failures do.","commonSituations":"Mis-escaping a registered TLS config name, or a generated DSN that introduces a stray '%'.","solutions":["Reference a registered config by a clean plain name, e.g. '?tls=custom', after calling mysql.RegisterTLSConfig(\"custom\", cfg).","Use a literal ('true', 'skip-verify', 'preferred') if you only need basic TLS behavior.","Percent-encode any '%' in the name as %25."],"exampleFix":"// before\nsql.Open(\"mysql\", \"user@tcp(127.0.0.1:3306)/db?tls=custom%2\")\n// after\nsql.Open(\"mysql\", \"user@tcp(127.0.0.1:3306)/db?tls=custom\")","handlingStrategy":"validation","validationCode":"// Confirm the tls value is a literal or decodes as a name.\nimport (\n    \"net/url\"\n    \"strings\"\n)\nfunc validTLSVal(v string) bool {\n    switch strings.ToLower(v) {\n    case \"true\",\"false\",\"skip-verify\",\"preferred\":\n        return true\n    }\n    _, err := url.QueryUnescape(v)\n    return err == nil\n}","typeGuard":"null","tryCatchPattern":"// Parse the DSN before opening to catch tls= decode errors early.\nif _, err := mysql.ParseDSN(dsn); err != nil {\n    return err\n}","preventionTips":["Prefer the built-in literals (true/skip-verify/preferred) unless you need a custom config.","Register TLS configs with simple ASCII names.","Validate generated DSNs with mysql.ParseDSN in tests."],"tags":["go","mysql","dsn","tls","security"],"backgroundTag":null,"analyzedSha":"03d76c7e07908e255ce62d126d07ede3f2365d86","analyzedAt":"2026-08-07T10:39:17.340Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}