jackc/pgx · error

require_auth method cannot be mixed with negative methods

Error message

require_auth method %q cannot be mixed with negative methods

What it means

The require_auth parameter mixed non-negated methods with negated ones, starting with negated. Like its sibling error, this means the list syntax is inconsistent; all entries must share the same negation style.

Solutions

  1. Remove the mixing of ! prefixed and plain methods
  2. Start with a non-negated method if using allow-list semantics
  3. Example: require_auth=scram-sha-256 to require one method
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgconn/require_auth.go:102 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/19eb71457311faec. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/require_auth.go:102

		neg := strings.HasPrefix(method, "!")
		if neg {
			method = method[1:]
		}
		if first {
			negated = neg
			if negated {
				// A negated list starts from "everything allowed, auth not required" and removes
				// methods; "!none" below flips authRequired back on.
				ra.allowed = 1<<authMethodCount - 1
			} else {
				ra.authRequired = true
			}
			first = false
		} else if neg != negated {
			if neg {
				return requireAuth{}, fmt.Errorf("negative require_auth method %q cannot be mixed with non-negative methods", method)
			}
			return requireAuth{}, fmt.Errorf("require_auth method %q cannot be mixed with negative methods", method)
		}

		var m authMethod
		switch method {
		case "password":
			m = authMethodPassword
		case "md5":
			m = authMethodMD5
		case "gss":
			m = authMethodGSS
		case "sspi":
			m = authMethodSSPI
		case "scram-sha-256":
			m = authMethodSCRAMSHA256
		case "oauth":
			m = authMethodOAuth
		case "none":
			m = authMethodNone

View on GitHub (pinned to ec1a0befd2)