{"record":{"id":"ae65f36c4939b8f2","repo":"mongodb/node-mongodb-native","slug":"password-cannot-be-empty","errorCode":null,"errorMessage":"Password cannot be empty","messagePattern":"Password cannot be empty","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/scram.ts","lineNumber":227,"sourceCode":"  const parts = payloadStr.split(',');\n  for (let i = 0; i < parts.length; i++) {\n    const valueParts = (parts[i].match(/^([^=]*)=(.*)$/) ?? []).slice(1);\n    dict[valueParts[0]] = valueParts[1];\n  }\n  return dict;\n}\n\nfunction passwordDigest(username: string, password: string) {\n  if (typeof username !== 'string') {\n    throw new MongoInvalidArgumentError('Username must be a string');\n  }\n\n  if (typeof password !== 'string') {\n    throw new MongoInvalidArgumentError('Password must be a string');\n  }\n\n  if (password.length === 0) {\n    throw new MongoInvalidArgumentError('Password cannot be empty');\n  }\n\n  let nodeCrypto;\n  try {\n    // TODO: NODE-7424 - remove dependency on 'crypto' for SCRAM-SHA-1 authentication\n    // eslint-disable-next-line @typescript-eslint/no-require-imports\n    nodeCrypto = require('crypto');\n  } catch (e) {\n    throw new MongoRuntimeError(\n      'Node.js crypto module is required for SCRAM-SHA-1 authentication',\n      {\n        cause: e\n      }\n    );\n  }\n\n  try {\n    const md5 = nodeCrypto.createHash('md5');","sourceCodeStart":209,"sourceCodeEnd":245,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/scram.ts#L209-L245","documentation":"Thrown as a MongoInvalidArgumentError inside passwordDigest() when the SCRAM-SHA-1 code path receives an empty password string. passwordDigest() is only invoked for the SCRAM-SHA-1 mechanism (sha256 uses saslprep instead), so this specifically guards the legacy MD5-based digest step. The check exists because an empty password produces an invalid MD5 digest and would yield a confusing server-side auth failure later.","triggerScenarios":"Connecting or authenticating with authMechanism 'SCRAM-SHA-1' (or MONGODB_DEFAULT that the server negotiates down to SCRAM-SHA-1) where the credentials object has a username but password === ''. Occurs during the SCRAM conversation in continueScramConversation() -> passwordDigest(username, password).","commonSituations":"Setting MONGODB_URI with username but no password (e.g. mongodb://user@host/db), reading credentials from an env var that is unset/empty, a service account whose password was rotated to empty, or a typo dropping the password segment of the URI.","solutions":["Supply a non-empty password in the connection string (mongodb://user:pass@host/db) or in the credentials passed to MongoClient","If auth is not required, remove the username from the URI so the driver does not attempt SCRAM","Verify the password environment variable is populated before constructing the MongoClient (check for empty string, not just undefined)"],"exampleFix":"// before\nconst client = new MongoClient('mongodb://myuser@host:27017/db');\n\n// after\nconst client = new MongoClient('mongodb://myuser:s3cret@host:27017/db');","handlingStrategy":"validation","validationCode":"const uri = process.env.MONGODB_URI ?? '';\nif (/^[^:]*:[^:@]*@/.test(uri) && /:\\/\\/[^:@]*:@/.test(uri)) {\n  throw new Error('MongoDB URI contains an empty password');\n}\n// or, with explicit credentials:\nconst { username, password } = creds;\nif (username && !password) throw new Error('Username set but password is empty');","typeGuard":"function hasValidPassword(creds: { username?: string; password?: string }): boolean {\n  return typeof creds.password === 'string' && creds.password.length > 0;\n}","tryCatchPattern":"try {\n  await client.connect();\n} catch (e) {\n  if (e instanceof MongoInvalidArgumentError && /Password cannot be empty/.test(e.message)) {\n    // fix credentials and retry\n  }\n  throw e;\n}","preventionTips":["Always validate that password is a non-empty string before constructing MongoClient","Use a secrets manager rather than interpolating possibly-empty env vars into the URI","Add a startup assertion that fails fast if auth env vars are missing"],"tags":["authentication","scram","credentials","configuration"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}