{"record":{"id":"7d2184301eaa6cd3","repo":"mongodb/node-mongodb-native","slug":"password-not-allowed-for-mechanism-mongodb-x509","errorCode":null,"errorMessage":"Password not allowed for mechanism MONGODB-X509","messagePattern":"Password not allowed for mechanism MONGODB-X509","errorType":"exception","errorClass":"MongoAPIError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongo_credentials.ts","lineNumber":270,"sourceCode":"        // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n        throw new MongoAPIError(\n          `Invalid source '${this.source}' for mechanism '${this.mechanism}' specified.`\n        );\n      }\n    }\n\n    if (this.mechanism === AuthMechanism.MONGODB_PLAIN && this.source == null) {\n      // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n      throw new MongoAPIError('PLAIN Authentication Mechanism needs an auth source');\n    }\n\n    if (this.mechanism === AuthMechanism.MONGODB_X509 && this.password != null) {\n      if (this.password === '') {\n        Reflect.set(this, 'password', undefined);\n        return;\n      }\n      // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n      throw new MongoAPIError(`Password not allowed for mechanism MONGODB-X509`);\n    }\n\n    const canonicalization = this.mechanismProperties.CANONICALIZE_HOST_NAME ?? false;\n    if (!Object.values(GSSAPICanonicalizationValue).includes(canonicalization)) {\n      throw new MongoAPIError(`Invalid CANONICALIZE_HOST_NAME value: ${canonicalization}`);\n    }\n  }\n\n  static merge(\n    creds: MongoCredentials | undefined,\n    options: Partial<MongoCredentialsOptions>\n  ): MongoCredentials {\n    return new MongoCredentials({\n      username: options.username ?? creds?.username ?? '',\n      password: options.password ?? creds?.password ?? '',\n      mechanism: options.mechanism ?? creds?.mechanism ?? AuthMechanism.MONGODB_DEFAULT,\n      mechanismProperties: options.mechanismProperties ?? creds?.mechanismProperties ?? {},\n      source: options.source ?? options.db ?? creds?.source ?? 'admin'","sourceCodeStart":252,"sourceCodeEnd":288,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongo_credentials.ts#L252-L288","documentation":"Thrown by MongoCredentials.validate() when MONGODB-X509 is used with a non-empty password. X509 authenticates via a client certificate distinguished name (the username), never a password; supplying one (other than an empty string, which is silently cleared) is treated as a configuration error.","triggerScenarios":"Setting authMechanism='MONGODB-X509' along with a password in the connection string or credentials object. Fires at validate() line 270 (only when password is non-empty; empty-string password is auto-cleared).","commonSituations":"Reusing a username/password template and only changing the mechanism. Tooling that always populates password. Misunderstanding that X509 uses the certificate, not a secret.","solutions":["Remove the password entirely from the connection string/options.","Ensure TLS client certificates are configured via tlsCertificateKeyFile / sslContext, not password.","Leave username as the certificate subject (RFC2253 DN) if required by your server."],"exampleFix":"// before\n'mongodb://host/?authMechanism=MONGODB-X509&username=CN%3Dapp&password=secret'\n// after\n'mongodb://host/?authMechanism=MONGODB-X509&username=CN%3Dapp'","handlingStrategy":"validation","validationCode":"function assertX509NoPassword(mech, password) {\n  if (mech === 'MONGODB-X509' && password != null && password !== '') {\n    throw new Error('MONGODB-X509 does not allow a password.');\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Never include password for X509 connection strings.","Load the client identity via tlsCertificateKeyFile, not credentials.","Strip password fields in your connection helper when mechanism is X509."],"tags":["authentication","x509","configuration","credentials"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}