{"record":{"id":"d1a00be3677bb49d","repo":"mongodb/node-mongodb-native","slug":"the-a-option-cannot-be-used-with-the-b-o","errorCode":null,"errorMessage":"The '${a}' option cannot be used with the '${b}' option","messagePattern":"The '(.+?)' option cannot be used with the '(.+?)' option","errorType":"exception","errorClass":"MongoAPIError","httpStatus":null,"severity":"error","filePath":"src/connection_string.ts","lineNumber":170,"sourceCode":"    throw new MongoParseError('Cannot combine replicaSet option with srvMaxHosts');\n  }\n\n  validateLoadBalancedOptions(hostAddresses, options, true);\n\n  return hostAddresses;\n}\n\n/**\n * Checks if TLS options are valid\n *\n * @param allOptions - All options provided by user or included in default options map\n * @throws MongoAPIError if TLS options are invalid\n */\nfunction checkTLSOptions(allOptions: CaseInsensitiveMap): void {\n  if (!allOptions) return;\n  const check = (a: string, b: string) => {\n    if (allOptions.has(a) && allOptions.has(b)) {\n      throw new MongoAPIError(`The '${a}' option cannot be used with the '${b}' option`);\n    }\n  };\n  check('tlsInsecure', 'tlsAllowInvalidCertificates');\n  check('tlsInsecure', 'tlsAllowInvalidHostnames');\n}\nfunction getBoolean(name: string, value: unknown): boolean {\n  if (typeof value === 'boolean') return value;\n  switch (value) {\n    case 'true':\n      return true;\n    case 'false':\n      return false;\n    default:\n      throw new MongoParseError(`${name} must be either \"true\" or \"false\"`);\n  }\n}\n\nfunction getIntFromOptions(name: string, value: unknown): number {","sourceCodeStart":152,"sourceCodeEnd":188,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/connection_string.ts#L152-L188","documentation":"TLS option conflict guard. tlsInsecure is a convenience flag that disables all certificate and hostname validation; using it alongside either tlsAllowInvalidCertificates or tlsAllowInvalidHostnames is redundant and confusing. checkTLSOptions throws to force the caller to choose one.","triggerScenarios":"Supplying tlsInsecure together with tlsAllowInvalidCertificates or tlsAllowInvalidHostnames in the URI query string or options object, parsed into the CaseInsensitiveMap of all provided options.","commonSituations":"A developer stacks every 'make TLS work' flag while fighting a self-signed cert, or migrates from older ssl config and forgets to remove redundant flags.","solutions":["Remove tlsInsecure and keep the specific tlsAllowInvalid* flag you need.","Or remove the tlsAllowInvalid* flags and keep only tlsInsecure."],"exampleFix":"// before\nnew MongoClient('mongodb://h/db?tls=true&tlsInsecure=true&tlsAllowInvalidCertificates=true');\n// after\nnew MongoClient('mongodb://h/db?tls=true&tlsAllowInvalidCertificates=true');","handlingStrategy":"validation","validationCode":"function assertNoTlsConflict(opts: Record<string, unknown>) {\n  const has = (k: string) => opts[k] != null;\n  if (has('tlsInsecure') && (has('tlsAllowInvalidCertificates') || has('tlsAllowInvalidHostnames'))) {\n    throw new Error('tlsInsecure cannot be combined with tlsAllowInvalidCertificates/tlsAllowInvalidHostnames');\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Standardize on one TLS-loosening flag in your codebase.","Avoid 'turn everything off' debugging stacks; commit to one flag before production."],"tags":["tls","connection-string","validation","security"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}