{"record":{"id":"a60c261c24298fcc","repo":"mongodb/node-mongodb-native","slug":"plain-authentication-mechanism-needs-an-auth-sourc","errorCode":null,"errorMessage":"PLAIN Authentication Mechanism needs an auth source","messagePattern":"PLAIN Authentication Mechanism needs an auth source","errorType":"exception","errorClass":"MongoAPIError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongo_credentials.ts","lineNumber":261,"sourceCode":"          if (typeof host !== 'string') {\n            throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);\n          }\n        }\n      }\n    }\n\n    if (AUTH_MECHS_AUTH_SRC_EXTERNAL.has(this.mechanism)) {\n      if (this.source != null && this.source !== '$external') {\n        // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n        throw new MongoAPIError(\n          `Invalid source '${this.source}' for mechanism '${this.mechanism}' specified.`\n        );\n      }\n    }\n\n    if (this.mechanism === AuthMechanism.MONGODB_PLAIN && this.source == null) {\n      // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n      throw new MongoAPIError('PLAIN Authentication Mechanism needs an auth source');\n    }\n\n    if (this.mechanism === AuthMechanism.MONGODB_X509 && this.password != null) {\n      if (this.password === '') {\n        Reflect.set(this, 'password', undefined);\n        return;\n      }\n      // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n      throw new MongoAPIError(`Password not allowed for mechanism MONGODB-X509`);\n    }\n\n    const canonicalization = this.mechanismProperties.CANONICALIZE_HOST_NAME ?? false;\n    if (!Object.values(GSSAPICanonicalizationValue).includes(canonicalization)) {\n      throw new MongoAPIError(`Invalid CANONICALIZE_HOST_NAME value: ${canonicalization}`);\n    }\n  }\n\n  static merge(","sourceCodeStart":243,"sourceCodeEnd":279,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongo_credentials.ts#L243-L279","documentation":"Thrown by MongoCredentials.validate() when MONGODB-PLAIN is used but no auth source is supplied. PLAIN (LDAP) authentication is not performed against the default 'admin' database in many deployments, so the driver requires an explicit source to know where to send credentials.","triggerScenarios":"Configuring authMechanism='PLAIN' without an authSource (and no default resolves). Fires at validate() line 261 where this.source == null.","commonSituations":"Setting up LDAP/PLAIN auth and forgetting authSource. The connection string lacks authSource and no db fallback applies.","solutions":["Add authSource to the connection string (commonly '$external' for LDAP).","In code, pass credentials with source:'$external' (or your LDAP auth database).","Confirm with your LDAP/MongoDB admin which database PLAIN auth targets."],"exampleFix":"// before\nnew MongoClient(url, { auth: { mechanism:'PLAIN', username:'u', password:'p' } });\n// after\nnew MongoClient(url, { auth: { mechanism:'PLAIN', username:'u', password:'p', source:'$external' } });","handlingStrategy":"validation","validationCode":"function assertPlainSource(mech, source) {\n  if (mech === 'PLAIN' && source == null) {\n    throw new Error('MONGODB-PLAIN requires an authSource (often $external).');\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always specify authSource when configuring PLAIN/LDAP.","Confirm the LDAP auth database with your administrator.","Add a config-layer check for PLAIN mechanism."],"tags":["authentication","plain","ldap","configuration","auth-source"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}