{"record":{"id":"be58ad1e3cd00a76","repo":"sidorares/node-mysql2","slug":"ssl-profile-must-be-an-object-instead-it-s-a-ty","errorCode":null,"errorMessage":"SSL profile must be an object, instead it's a ${typeof this.ssl}","messagePattern":"SSL profile must be an object, instead it's a (.+?)","errorType":"validation","errorClass":"TypeError","httpStatus":null,"severity":"error","filePath":"lib/connection_config.js","lineNumber":166,"sourceCode":"        ? ConnectionConfig.getSSLProfile(options.ssl)\n        : options.ssl || false;\n    this.multipleStatements = options.multipleStatements || false;\n    this.rowsAsArray = options.rowsAsArray || false;\n    this.namedPlaceholders = options.namedPlaceholders || false;\n    this.nestTables =\n      options.nestTables === undefined ? undefined : options.nestTables;\n    this.typeCast = options.typeCast === undefined ? true : options.typeCast;\n    this.disableEval = Boolean(options.disableEval);\n    this.enableCleartextPlugin = Boolean(options.enableCleartextPlugin);\n    if (this.timezone[0] === ' ') {\n      // \"+\" is a url encoded char for space so it\n      // gets translated to space when giving a\n      // connection string..\n      this.timezone = `+${this.timezone.slice(1)}`;\n    }\n    if (this.ssl) {\n      if (typeof this.ssl !== 'object') {\n        throw new TypeError(\n          `SSL profile must be an object, instead it's a ${typeof this.ssl}`\n        );\n      }\n      // Default rejectUnauthorized to true\n      this.ssl.rejectUnauthorized = this.ssl.rejectUnauthorized !== false;\n    }\n    this.maxPacketSize = 0;\n    this.charsetNumber = options.charset\n      ? ConnectionConfig.getCharsetNumber(options.charset)\n      : options.charsetNumber || Charsets.UTF8MB4_UNICODE_CI;\n    this.compress = options.compress || false;\n    this.authPlugins = options.authPlugins;\n    this.authSwitchHandler = options.authSwitchHandler;\n    this.clientFlags = ConnectionConfig.mergeFlags(\n      ConnectionConfig.getDefaultFlags(options),\n      options.flags || ''\n    );\n    // Default connection attributes","sourceCodeStart":148,"sourceCodeEnd":184,"githubUrl":"https://github.com/sidorares/node-mysql2/blob/8b1f829d3706404ab372cf97bd77ebcf86578d97/lib/connection_config.js#L148-L184","documentation":"After ConnectionConfig resolves the ssl option (lib/connection_config.js:146-172) — converting a string to an SSL profile and leaving other values as-is — it asserts that a truthy ssl is an object. A truthy non-object (e.g. a number, or a string that somehow bypassed conversion) indicates malformed config and throws a TypeError. A boolean true is an object-boxed Boolean? No — typeof true === 'boolean', so passing ssl: true would NOT trigger this (the code path makes ssl the boolean true only when options.ssl is absent/false); the throw fires for non-string, non-object truthy values.","triggerScenarios":"Passing ssl: 1 or ssl: 'true' where 'true' is not a known profile name (string branch resolves via getSSLProfile which would throw Unknown SSL profile first); passing a serialized JSON string that did not match a profile; passing an array as ssl.","commonSituations":"Reading ssl from an env var and coercing loosely (ssl: Number(process.env.SSL)); passing a config object built by a helper that returns a non-object on a missing key.","solutions":["Pass ssl as an object: ssl: { rejectUnauthorized: true } or as a known profile name string.","Pass ssl: true for default TLS (the code accepts boolean true), or omit for no SSL.","Sanitize env-derived ssl values: const ssl = process.env.SSL === 'true' ? { rejectUnauthorized: true } : false."],"exampleFix":"// before\ncreateConnection({ ssl: process.env.SSL_PORT }); // a number/string that is not a profile\n\n// after\ncreateConnection({ ssl: { rejectUnauthorized: true } });","handlingStrategy":"validation","validationCode":"function normalizeSsl(ssl) {\n  if (ssl === true) return { rejectUnauthorized: true };\n  if (ssl === false || ssl == null) return false;\n  if (typeof ssl === 'string') return ssl; // profile name\n  if (typeof ssl === 'object') return ssl;\n  throw new TypeError(`ssl must be boolean|string|object, got ${typeof ssl}`);\n}\n// createConnection({ ..., ssl: normalizeSsl(rawSsl) });","typeGuard":"const isSslOption = (v) => v === true || v === false || typeof v === 'string' || (typeof v === 'object' && v !== null);","tryCatchPattern":null,"preventionTips":["Always type the ssl config field explicitly (boolean | string | object).","Sanitize env-derived ssl with an explicit normalize helper."],"tags":["ssl","connection-config","validation","tls"],"backgroundTag":null,"analyzedSha":"8b1f829d3706404ab372cf97bd77ebcf86578d97","analyzedAt":"2026-08-11T02:54:28.964Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}