{"record":{"id":"74b26fbee5675206","repo":"redis/node-redis","slug":"tls-socket-option-is-set-to-options-socket-tls","errorCode":null,"errorMessage":"tls socket option is set to ${options.socket.tls} which is mismatch with protocol or the URL ${options.url} passed","messagePattern":"tls socket option is set to (.+?) which is mismatch with protocol or the URL (.+?) passed","errorType":"validation","errorClass":"TypeError","httpStatus":null,"severity":"error","filePath":"packages/client/lib/client/index.ts","lineNumber":457,"sourceCode":"    };\n  }\n\n  static create<\n    M extends RedisModules = {},\n    F extends RedisFunctions = {},\n    S extends RedisScripts = {},\n    RESP extends RespVersions = 3,\n    TYPE_MAPPING extends TypeMapping = {}\n  >(this: void, options?: RedisClientOptions<M, F, S, RESP, TYPE_MAPPING>) {\n    return RedisClient.factory(options)(options);\n  }\n\n  static parseOptions<O extends AnyRedisClientOptions>(options: O): O {\n    if (options?.url) {\n      const parsed = RedisClient.parseURL(options.url);\n      if (options.socket) {\n        if (options.socket.tls !== undefined && options.socket.tls !== parsed.socket.tls) {\n          throw new TypeError(`tls socket option is set to ${options.socket.tls} which is mismatch with protocol or the URL ${options.url} passed`)\n        }\n        parsed.socket = Object.assign(options.socket, parsed.socket);\n      }\n\n      Object.assign(options, parsed);\n    }\n    return options;\n  }\n\n  static parseURL(url: string): AnyRedisClientOptions & {\n    socket: Exclude<AnyRedisClientOptions['socket'], undefined> & {\n      tls: boolean\n    }\n  } {\n    // unix:// URIs use a non-special scheme; WHATWG URL refuses to parse an\n    // authority (e.g. `user:pass@`) without a host, so handle it separately.\n    if (url.startsWith('unix:')) {\n      return RedisClient.#parseUnixURL(url);","sourceCodeStart":439,"sourceCodeEnd":475,"githubUrl":"https://github.com/redis/node-redis/blob/90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58/packages/client/lib/client/index.ts#L439-L475","documentation":"When both url and socket.tls are supplied to createClient, the explicit tls flag must agree with the URL scheme: rediss:// implies tls true, redis:// implies tls false. A mismatch is rejected to prevent silently opening an insecure connection the user thought was encrypted (or vice-versa).","triggerScenarios":"createClient({ url: 'redis://host:6379', socket: { tls: true } }) or createClient({ url: 'rediss://host:6379', socket: { tls: false } }).","commonSituations":"Copy-pasting url and tls options from different examples; switching scheme without removing the explicit flag; running behind a TLS-terminating proxy where the user toggles tls but not the scheme.","solutions":["Drop the redundant socket.tls and let the URL drive it.","Make the URL and the tls flag agree (use rediss:// with tls:true, or redis:// with tls:false)."],"exampleFix":"// before\ncreateClient({ url: 'redis://host:6379', socket: { tls: true } });\n\n// after\ncreateClient({ url: 'rediss://host:6379', socket: { tls: true } });\n// or\ncreateClient({ url: 'rediss://host:6379' });","handlingStrategy":"validation","validationCode":"function resolveRedisUrl(options) {\n  const wantsTls = Boolean(options.socket?.tls);\n  const urlIsTls = options.url?.startsWith('rediss://');\n  const urlIsPlain = options.url?.startsWith('redis://');\n  if (options.url && options.socket?.tls !== undefined && (\n    (wantsTls && urlIsPlain) || (!wantsTls && urlIsTls)\n  )) {\n    throw new TypeError(`tls flag ${wantsTls} conflicts with URL scheme ${options.url}`);\n  }\n  return options;\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Pick one source of truth for TLS: either the URL scheme or socket.tls, not both.","When migrating from redis:// to rediss://, drop any explicit socket.tls.","Validate the combination at config load."],"tags":["config","tls","url","validation"],"backgroundTag":null,"analyzedSha":"90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58","analyzedAt":"2026-08-11T15:37:21.243Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}