{"record":{"id":"509e517563ee3feb","repo":"mongodb/node-mongodb-native","slug":"auth-mechanism-property-allowed-hosts-must-be-an-a","errorCode":null,"errorMessage":"Auth mechanism property ALLOWED_HOSTS must be an array of strings.","messagePattern":"Auth mechanism property ALLOWED_HOSTS must be an array of strings\\.","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongo_credentials.ts","lineNumber":240,"sourceCode":"            ','\n          )} is supported for mechanism '${this.mechanism}'.`\n        );\n      }\n\n      if (\n        !this.mechanismProperties.ENVIRONMENT &&\n        !this.mechanismProperties.OIDC_CALLBACK &&\n        !this.mechanismProperties.OIDC_HUMAN_CALLBACK\n      ) {\n        throw new MongoInvalidArgumentError(\n          `Either a ENVIRONMENT, OIDC_CALLBACK, or OIDC_HUMAN_CALLBACK must be specified for mechanism '${this.mechanism}'.`\n        );\n      }\n\n      if (this.mechanismProperties.ALLOWED_HOSTS) {\n        const hosts = this.mechanismProperties.ALLOWED_HOSTS;\n        if (!Array.isArray(hosts)) {\n          throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);\n        }\n        for (const host of hosts) {\n          if (typeof host !== 'string') {\n            throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);\n          }\n        }\n      }\n    }\n\n    if (AUTH_MECHS_AUTH_SRC_EXTERNAL.has(this.mechanism)) {\n      if (this.source != null && this.source !== '$external') {\n        // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n        throw new MongoAPIError(\n          `Invalid source '${this.source}' for mechanism '${this.mechanism}' specified.`\n        );\n      }\n    }\n","sourceCodeStart":222,"sourceCodeEnd":258,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongo_credentials.ts#L222-L258","documentation":"Thrown by MongoCredentials.validate() when the MONGODB-OIDC ALLOWED_HOSTS property is present but is not an Array. ALLOWED_HOSTS restricts which hostnames may receive the OIDC token (SSRF protection) and must be an array of strings; a non-array value is rejected before any network call.","triggerScenarios":"Setting authMechanismProperties.ALLOWED_HOSTS to a string, object, number, or any non-array value while using MONGODB-OIDC. Fires in validate() at line 240.","commonSituations":"Passing a single host as a string (e.g. 'localhost') instead of ['localhost']. Mis-formatting the connection-string authMechanismProperties (ALLOWED_HOSTS:localhost instead of ALLOWED_HOSTS:localhost,127.0.0.1).","solutions":["Provide ALLOWED_HOSTS as an array of strings, e.g. ['localhost','*.mongodb.net'].","If overriding defaults, ensure the value is literally an Array in the JS options object.","Omit ALLOWED_HOSTS entirely to use DEFAULT_ALLOWED_HOSTS if you do not need custom hosts."],"exampleFix":"// before\nmechanismProperties: { ENVIRONMENT:'test', ALLOWED_HOSTS: 'localhost' }\n// after\nmechanismProperties: { ENVIRONMENT:'test', ALLOWED_HOSTS: ['localhost'] }","handlingStrategy":"type-guard","validationCode":"function assertAllowedHosts(props) {\n  if ('ALLOWED_HOSTS' in props && !Array.isArray(props.ALLOWED_HOSTS)) {\n    throw new Error('ALLOWED_HOSTS must be an array.');\n  }\n}","typeGuard":"function isStringArray(v): v is string[] {\n  return Array.isArray(v) && v.every(x => typeof x === 'string');\n}","tryCatchPattern":null,"preventionTips":["Always pass ALLOWED_HOSTS as an array literal.","Omit the property to inherit DEFAULT_ALLOWED_HOSTS unless you need custom hosts.","Add a runtime guard in your config layer."],"tags":["authentication","oidc","configuration","validation"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}