{"record":{"id":"693f243481802dce","repo":"websockets/ws","slug":"invalid-value-for-parameter-key-value","errorCode":null,"errorMessage":"Invalid value for parameter \"${key}\": ${value}","messagePattern":"Invalid value for parameter \"(.+?)\": (.+?)","errorType":"exception","errorClass":"TypeError","httpStatus":null,"severity":"error","filePath":"lib/permessage-deflate.js","lineNumber":261,"sourceCode":"   * @return {Array} The offers/response with normalized parameters\n   * @private\n   */\n  normalizeParams(configurations) {\n    configurations.forEach((params) => {\n      Object.keys(params).forEach((key) => {\n        let value = params[key];\n\n        if (value.length > 1) {\n          throw new Error(`Parameter \"${key}\" must have only a single value`);\n        }\n\n        value = value[0];\n\n        if (key === 'client_max_window_bits') {\n          if (value !== true) {\n            const num = +value;\n            if (!Number.isInteger(num) || num < 8 || num > 15) {\n              throw new TypeError(\n                `Invalid value for parameter \"${key}\": ${value}`\n              );\n            }\n            value = num;\n          } else if (!this._isServer) {\n            throw new TypeError(\n              `Invalid value for parameter \"${key}\": ${value}`\n            );\n          }\n        } else if (key === 'server_max_window_bits') {\n          const num = +value;\n          if (!Number.isInteger(num) || num < 8 || num > 15) {\n            throw new TypeError(\n              `Invalid value for parameter \"${key}\": ${value}`\n            );\n          }\n          value = num;\n        } else if (","sourceCodeStart":243,"sourceCodeEnd":279,"githubUrl":"https://github.com/websockets/ws/blob/c791e707eab3c13dd9a261d2479c3cc4a49a6fed/lib/permessage-deflate.js#L243-L279","documentation":"Thrown (as TypeError) by `PerMessageDeflate.normalizeParams()` when validating `client_max_window_bits`: the value is not the bare flag `true`, and coercing it with `+value` does not yield an integer in the allowed range [8, 15] defined by RFC 7692. The offending `value` is interpolated into the message.","triggerScenarios":"A peer offers `client_max_window_bits=7`, `client_max_window_bits=16`, `client_max_window_bits=abc`, or any non-numeric, non-`true` value; `normalizeParams` (called from `accept()`) throws.","commonSituations":"A buggy peer advertises an out-of-range window size; a fuzzer; a misconfigured client passing a string instead of a number.","solutions":["Ensure `client_max_window_bits` is either the bare flag (`true`, advertised without a value) or an integer between 8 and 15 inclusive.","Generate offers with the library's `offer()` method rather than hand-coding them.","Catch the TypeError during the handshake and close with code 1002."],"exampleFix":"// before\npmd.normalizeParams([{ client_max_window_bits: ['7'] }]);\n\n// after\npmd.normalizeParams([{ client_max_window_bits: ['12'] }]);","handlingStrategy":"validation","validationCode":"// Validate client_max_window_bits before negotiation.\nfunction validClientMaxWindowBits(v) {\n  return v === true || (Number.isInteger(+v) && +v >= 8 && +v <= 15);\n}","typeGuard":null,"tryCatchPattern":"try {\n  perMessageDeflate.accept(parsedOffers);\n} catch (err) {\n  if (err instanceof TypeError && /client_max_window_bits/.test(err.message)) {\n    abortHandshake(socket, 1002);\n    return;\n  }\n  throw err;\n}","preventionTips":["Ensure `client_max_window_bits` is `true` or an integer in [8, 15].","Build offers with `PerMessageDeflate.prototype.offer()` rather than hand-coding parameters.","Validate parameters before calling `accept()` when peers are untrusted."],"tags":["websocket","compression","permessage-deflate","negotiation","validation","rfc7692"],"backgroundTag":null,"analyzedSha":"c791e707eab3c13dd9a261d2479c3cc4a49a6fed","analyzedAt":"2026-08-06T19:07:51.047Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}