{"record":{"id":"e916dd07b5982d81","repo":"mongodb/node-mongodb-native","slug":"invalid-source-this-source-for-mechanism-t","errorCode":null,"errorMessage":"Invalid source '${this.source}' for mechanism '${this.mechanism}' specified.","messagePattern":"Invalid source '(.+?)' for mechanism '(.+?)' specified\\.","errorType":"exception","errorClass":"MongoAPIError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongo_credentials.ts","lineNumber":253,"sourceCode":"      }\n\n      if (this.mechanismProperties.ALLOWED_HOSTS) {\n        const hosts = this.mechanismProperties.ALLOWED_HOSTS;\n        if (!Array.isArray(hosts)) {\n          throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);\n        }\n        for (const host of hosts) {\n          if (typeof host !== 'string') {\n            throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);\n          }\n        }\n      }\n    }\n\n    if (AUTH_MECHS_AUTH_SRC_EXTERNAL.has(this.mechanism)) {\n      if (this.source != null && this.source !== '$external') {\n        // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n        throw new MongoAPIError(\n          `Invalid source '${this.source}' for mechanism '${this.mechanism}' specified.`\n        );\n      }\n    }\n\n    if (this.mechanism === AuthMechanism.MONGODB_PLAIN && this.source == null) {\n      // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n      throw new MongoAPIError('PLAIN Authentication Mechanism needs an auth source');\n    }\n\n    if (this.mechanism === AuthMechanism.MONGODB_X509 && this.password != null) {\n      if (this.password === '') {\n        Reflect.set(this, 'password', undefined);\n        return;\n      }\n      // TODO(NODE-3485): Replace this with a MongoAuthValidationError\n      throw new MongoAPIError(`Password not allowed for mechanism MONGODB-X509`);\n    }","sourceCodeStart":235,"sourceCodeEnd":271,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongo_credentials.ts#L235-L271","documentation":"Thrown by MongoCredentials.validate() when an external-source auth mechanism (GSSAPI, MONGODB-AWS, MONGODB-OIDC, MONGODB-X509) is configured with an authSource other than '$external'. These mechanisms always authenticate against the '$external' database, so any other source is invalid.","triggerScenarios":"Setting authSource=<db> in the connection string or credentials while using GSSAPI/AWS/OIDC/X509. Fires in validate() via the AUTH_MECHS_AUTH_SRC_EXTERNAL set check.","commonSituations":"Carrying over authSource=admin from a SCRAM connection string. Explicitly setting source:'admin' in code. Tools/generators that auto-append authSource.","solutions":["Remove the authSource parameter, or set it explicitly to '$external'.","For these mechanisms, do not specify a source at all and let the driver default correctly.","Audit your connection string/template for stray authSource values."],"exampleFix":"// before\n'mongodb://host/?authMechanism=MONGODB-X509&authSource=admin'\n// after\n'mongodb://host/?authMechanism=MONGODB-X509&authSource=$external'","handlingStrategy":"validation","validationCode":"const EXTERNAL_MECHS = ['GSSAPI','MONGODB-AWS','MONGODB-OIDC','MONGODB-X509'];\nfunction assertExternalSource(mech, source) {\n  if (EXTERNAL_MECHS.includes(mech) && source != null && source !== '$external') {\n    throw new Error(`authSource must be $external for ${mech}`);\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Do not set authSource for external mechanisms; let the driver default.","Audit connection-string templates for stale authSource=admin.","Document that GSSAPI/AWS/OIDC/X509 always use $external."],"tags":["authentication","configuration","auth-source","credentials"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}