{"record":{"id":"ef3be7128e9dd93e","repo":"mongodb/node-mongodb-native","slug":"cannot-set-both-proxyoptions-and-kmsconnectcallbac","errorCode":null,"errorMessage":"Cannot set both proxyOptions and kmsConnectCallback","messagePattern":"Cannot set both proxyOptions and kmsConnectCallback","errorType":"exception","errorClass":"MongoCryptInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/auto_encrypter.ts","lineNumber":254,"sourceCode":"   *       cryptSharedLibRequired: true\n   *     }\n   *   }\n   * });\n   * ```\n   *\n   * await client.connect();\n   * // From here on, the client will be encrypting / decrypting automatically\n   */\n  constructor(client: MongoClient, options: AutoEncryptionOptions) {\n    this._client = client;\n    this._bypassEncryption = options.bypassAutoEncryption === true;\n\n    this._keyVaultNamespace = options.keyVaultNamespace || 'admin.datakeys';\n    this._keyVaultClient = options.keyVaultClient || client;\n    this._metaDataClient = options.metadataClient || client;\n    this._proxyOptions = options.proxyOptions || {};\n    if (this._proxyOptions.proxyHost && options.kmsConnectCallback) {\n      throw new MongoCryptInvalidArgumentError(\n        'Cannot set both proxyOptions and kmsConnectCallback'\n      );\n    }\n    this._tlsOptions = options.tlsOptions || {};\n    this._kmsConnectCallback = options.kmsConnectCallback;\n    this._kmsProviders = options.kmsProviders || {};\n    this._credentialProviders = options.credentialProviders;\n\n    if (options.credentialProviders?.aws && !isEmptyCredentials('aws', this._kmsProviders)) {\n      throw new MongoCryptInvalidArgumentError(\n        'Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching'\n      );\n    }\n\n    const mongoCryptOptions: MongoCryptOptions = {\n      errorWrapper: defaultErrorWrapper\n    };\n    if (options.schemaMap) {","sourceCodeStart":236,"sourceCodeEnd":272,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/auto_encrypter.ts#L236-L272","documentation":"Thrown by the AutoEncrypter constructor when both proxyOptions (with a proxyHost) and kmsConnectCallback are provided in the autoEncryption configuration. These are two mutually exclusive mechanisms for controlling how the driver connects to KMS providers: proxyOptions configures a SOCKS5 proxy, while kmsConnectCallback provides a custom socket factory. This is a MongoCryptInvalidArgumentError.","triggerScenarios":"Creating a MongoClient with autoEncryption options that include both proxyOptions: { proxyHost: '...' } and kmsConnectCallback: fn. The constructor validates this before any connection is attempted.","commonSituations":"Configuring CSFLE behind a corporate proxy and mistakenly providing both SOCKS5 proxy settings and a custom HTTP CONNECT callback; merging configuration objects from different sources without removing the conflicting key.","solutions":["Use only one KMS connection mechanism: either proxyOptions or kmsConnectCallback, not both","If you need an HTTP CONNECT proxy, use kmsConnectCallback and remove proxyOptions","If you need a SOCKS5 proxy, use proxyOptions and remove kmsConnectCallback"],"exampleFix":"// before\nnew MongoClient(uri, {\n  autoEncryption: {\n    proxyOptions: { proxyHost: 'proxy.example.com', proxyPort: 1080 },\n    kmsConnectCallback: myCallback,\n    kmsProviders: { ... }\n  }\n});\n\n// after (choose one)\nnew MongoClient(uri, {\n  autoEncryption: {\n    kmsConnectCallback: myCallback,\n    kmsProviders: { ... }\n  }\n});","handlingStrategy":"validation","validationCode":"// Before creating the MongoClient\nconst { proxyOptions, kmsConnectCallback } = autoEncryptionConfig;\nif (proxyOptions?.proxyHost && kmsConnectCallback) {\n  throw new Error('Cannot set both proxyOptions and kmsConnectCallback; choose one');\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Review autoEncryption options before constructing MongoClient","Understand that proxyOptions (SOCKS5) and kmsConnectCallback (custom socket) are mutually exclusive","When merging config objects, check for conflicting KMS connection keys"],"tags":["csfle","configuration","kms","proxy"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}