mongodb/node-mongodb-native · error · MongoParseError

Auth mechanism property ALLOWED_HOSTS is not allowed in the…

Error message

Auth mechanism property ALLOWED_HOSTS is not allowed in the connection string.

What it means

ALLOWED_HOSTS is an OIDC auth-mechanism property that controls which hosts the driver may redirect to during OIDC token exchange. For security it must be supplied programmatically (via the options object), never via the connection string, so an attacker-controlled URI cannot redirect credentials. The driver scans authMechanismProperties values in the URI and rejects any containing 'ALLOWED_HOSTS:'.

Solutions

  1. Remove ALLOWED_HOSTS from the URI authMechanismProperties.
  2. Configure authMechanismProperties (including ALLOWED_HOSTS) via the options object instead.

Example fix

// before
new MongoClient('mongodb://h/db?authMechanism=MONGODB-OIDC&authMechanismProperties=ALLOWED_HOSTS:example.com');
// after
new MongoClient('mongodb://h/db?authMechanism=MONGODB-OIDC', { authMechanismProperties: { ALLOWED_HOSTS: 'example.com' } });
Defensive patterns

Strategy: validation

Validate before calling

function assertNoAllowedHostsInUri(uri: string) {
  const q = uri.split('?')[1] ?? '';
  if (/authMechanismProperties=[^&]*ALLOWED_HOSTS:/i.test(q)) {
    throw new Error('ALLOWED_HOSTS must be set via options.authMechanismProperties, not the URI');
  }
}

Prevention

When it happens

Trigger: A URI containing 'authMechanismProperties=ALLOWED_HOSTS:example.com' (or any comma-separated variant matching the regex). Checked after urlOptions are collected.

Common situations: Copy-pasting OIDC config into the connection string for convenience, or older examples that predate this restriction.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/03516672c8eb9e81. Report an issue: GitHub.

Appendix: source

Thrown at src/connection_string.ts:322

  }

  const objectOptions = new CaseInsensitiveMap<unknown>(
    Object.entries(options).filter(([, v]) => v != null)
  );

  // Validate options that can only be provided by one of uri or object

  if (urlOptions.has('serverApi')) {
    throw new MongoParseError(
      'URI cannot contain `serverApi`, it can only be passed to the client'
    );
  }

  const uriMechanismProperties = urlOptions.get('authMechanismProperties');
  if (uriMechanismProperties) {
    for (const property of uriMechanismProperties) {
      if (/(^|,)ALLOWED_HOSTS:/.test(property as string)) {
        throw new MongoParseError(
          'Auth mechanism property ALLOWED_HOSTS is not allowed in the connection string.'
        );
      }
    }
  }

  if (objectOptions.has('loadBalanced')) {
    throw new MongoParseError('loadBalanced is only a valid option in the URI');
  }

  // All option collection

  const allProvidedOptions = new CaseInsensitiveMap<unknown[]>();

  const allProvidedKeys = new Set<string>([...urlOptions.keys(), ...objectOptions.keys()]);

  for (const key of allProvidedKeys) {
    const values = [];

View on GitHub (pinned to dce7939f86)