{"record":{"id":"c610f430788a64bd","repo":"go-sql-driver/mysql","slug":"invalid-value-for-server-pub-key-name-v","errorCode":null,"errorMessage":"invalid value for server pub key name: %v","messagePattern":"invalid value for server pub key name: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"dsn.go","lineNumber":632,"sourceCode":"\t\tcase \"readTimeout\":\n\t\t\tcfg.ReadTimeout, err = time.ParseDuration(value)\n\t\t\tif err != nil {\n\t\t\t\treturn\n\t\t\t}\n\n\t\t// Reject read-only connections\n\t\tcase \"rejectReadOnly\":\n\t\t\tvar isBool bool\n\t\t\tcfg.RejectReadOnly, isBool = readBool(value)\n\t\t\tif !isBool {\n\t\t\t\treturn errors.New(\"invalid bool value: \" + value)\n\t\t\t}\n\n\t\t// Server public key\n\t\tcase \"serverPubKey\":\n\t\t\tname, err := url.QueryUnescape(value)\n\t\t\tif err != nil {\n\t\t\t\treturn fmt.Errorf(\"invalid value for server pub key name: %v\", err)\n\t\t\t}\n\t\t\tcfg.ServerPubKey = name\n\n\t\t// Strict mode\n\t\tcase \"strict\":\n\t\t\tpanic(\"strict mode has been removed. See https://github.com/go-sql-driver/mysql/wiki/strict-mode\")\n\n\t\t// Dial Timeout\n\t\tcase \"timeout\":\n\t\t\tcfg.Timeout, err = time.ParseDuration(value)\n\t\t\tif err != nil {\n\t\t\t\treturn\n\t\t\t}\n\n\t\t// TLS-Encryption\n\t\tcase \"tls\":\n\t\t\tboolValue, isBool := readBool(value)\n\t\t\tif isBool {","sourceCodeStart":614,"sourceCodeEnd":650,"githubUrl":"https://github.com/go-sql-driver/mysql/blob/03d76c7e07908e255ce62d126d07ede3f2365d86/dsn.go#L614-L650","documentation":"The 'serverPubKey' DSN parameter names a server public key registered via mysql.RegisterServerPubKey (used for sha256_password/caching_sha2_password key exchange). Its value is url.QueryUnescape'd; a malformed percent-escape in the value produces this error wrapping the unescape failure.","triggerScenarios":"A DSN like '?serverPubKey=%ZZ' or any value where '%' is not followed by two hex digits, and the value is meant to reference a registered public-key name.","commonSituations":"Rare, since the value is usually a plain ASCII name. Occurs when the name is generated or escaped incorrectly, or a stray '%' is introduced.","solutions":["Use a plain ASCII name that exactly matches a key added with mysql.RegisterServerPubKey.","If the name must contain '%', encode it as %25.","Avoid special characters in registered public-key names."],"exampleFix":"// before\nsql.Open(\"mysql\", \"user@tcp(127.0.0.1:3306)/db?serverPubKey=my%key\")\n// after\nsql.Open(\"mysql\", \"user@tcp(127.0.0.1:3306)/db?serverPubKey=my%25key\")","handlingStrategy":"validation","validationCode":"// Ensure the value query-unescapes cleanly.\nimport \"net/url\"\nif _, err := url.QueryUnescape(pubKeyName); err != nil {\n    return err\n}","typeGuard":"null","tryCatchPattern":"// serverPubKey issues surface at DSN parse time; validate the DSN first.\nif _, err := mysql.ParseDSN(dsn); err != nil {\n    return err\n}","preventionTips":["Keep serverPubKey names to plain ASCII identifiers.","Register the key (RegisterServerPubKey) with the exact name used in the DSN.","Percent-escape any generated name with url.QueryEscape."],"tags":["go","mysql","dsn","security","tls","auth"],"backgroundTag":null,"analyzedSha":"03d76c7e07908e255ce62d126d07ede3f2365d86","analyzedAt":"2026-08-07T10:39:17.340Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}