{"record":{"id":"bcb741c0163f1cff","repo":"sidorares/node-mysql2","slug":"user-connection-config-property-must-be-a-string","errorCode":null,"errorMessage":"\"user\" connection config property must be a string","messagePattern":"\"user\" connection config property must be a string","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"lib/packets/change_user.js","lineNumber":86,"sourceCode":"          connectAttributes[attrNames[k]],\n          encoding\n        );\n      }\n      packet.writeLengthCodedNumber(keysLength);\n      for (let k = 0; k < attrNames.length; ++k) {\n        packet.writeLengthCodedString(attrNames[k], encoding);\n        packet.writeLengthCodedString(\n          connectAttributes[attrNames[k]],\n          encoding\n        );\n      }\n    }\n    return packet;\n  }\n\n  toPacket() {\n    if (typeof this.user !== 'string') {\n      throw new Error('\"user\" connection config property must be a string');\n    }\n    if (typeof this.database !== 'string') {\n      throw new Error('\"database\" connection config property must be a string');\n    }\n    // dry run: calculate resulting packet length\n    const p = this.serializeToBuffer(Packet.MockBuffer());\n    return this.serializeToBuffer(Buffer.allocUnsafe(p.offset));\n  }\n}\n\nmodule.exports = ChangeUser;\n","sourceCodeStart":68,"sourceCodeEnd":98,"githubUrl":"https://github.com/sidorares/node-mysql2/blob/8b1f829d3706404ab372cf97bd77ebcf86578d97/lib/packets/change_user.js#L68-L98","documentation":"ChangeUser.toPacket (lib/packets/change_user.js:84-87) serializes a COM_CHANGE_USER packet and validates that user is a string before writing it null-terminated. A non-string user (number, undefined-after-coalesce, object) would corrupt the packet framing, so the driver throws before serialization.","triggerScenarios":"Calling connection.changeUser({ user: 123 }) or passing a config object whose user field is undefined/number; reusing a request body directly as changeUser options where user came in as a non-string.","commonSituations":"Loose env coercion (user: Number(process.env.DB_USER)); passing the entire request.user object instead of request.user.id; defaulting user with || from a missing value yielding a non-string.","solutions":["Coerce explicitly: String(opts.user).","Validate typeof opts.user === 'string' before calling changeUser.","Fix the upstream source so user is always a string."],"exampleFix":"// before\nconnection.changeUser({ user: req.body.userId }); // number\n\n// after\nconnection.changeUser({ user: String(req.body.userId) });","handlingStrategy":"validation","validationCode":"function assertChangeUserOpts(opts) {\n  if (typeof opts.user !== 'string') throw new TypeError('changeUser: user must be string');\n}","typeGuard":"const isUserString = (opts) => typeof (opts && opts.user) === 'string';","tryCatchPattern":null,"preventionTips":["Always coerce user to String at the boundary that reads config/env.","Type the changeUser options argument strictly."],"tags":["change-user","connection-config","validation","serialization"],"backgroundTag":null,"analyzedSha":"8b1f829d3706404ab372cf97bd77ebcf86578d97","analyzedAt":"2026-08-11T02:54:28.964Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}