mongodb/node-mongodb-native · error · MongoParseError
Auth mechanism property ALLOWED_HOSTS is not allowed in the…
Error message
Auth mechanism property ALLOWED_HOSTS is not allowed in the connection string.
What it means
ALLOWED_HOSTS is an OIDC auth-mechanism property that controls which hosts the driver may redirect to during OIDC token exchange. For security it must be supplied programmatically (via the options object), never via the connection string, so an attacker-controlled URI cannot redirect credentials. The driver scans authMechanismProperties values in the URI and rejects any containing 'ALLOWED_HOSTS:'.
Solutions
- Remove ALLOWED_HOSTS from the URI authMechanismProperties.
- Configure authMechanismProperties (including ALLOWED_HOSTS) via the options object instead.
Example fix
// before
new MongoClient('mongodb://h/db?authMechanism=MONGODB-OIDC&authMechanismProperties=ALLOWED_HOSTS:example.com');
// after
new MongoClient('mongodb://h/db?authMechanism=MONGODB-OIDC', { authMechanismProperties: { ALLOWED_HOSTS: 'example.com' } }); Defensive patterns
Strategy: validation
Validate before calling
function assertNoAllowedHostsInUri(uri: string) {
const q = uri.split('?')[1] ?? '';
if (/authMechanismProperties=[^&]*ALLOWED_HOSTS:/i.test(q)) {
throw new Error('ALLOWED_HOSTS must be set via options.authMechanismProperties, not the URI');
}
} Prevention
- Treat the connection string as untrusted for security-sensitive options.
- Configure OIDC authMechanismProperties programmatically.
When it happens
Trigger: A URI containing 'authMechanismProperties=ALLOWED_HOSTS:example.com' (or any comma-separated variant matching the regex). Checked after urlOptions are collected.
Common situations: Copy-pasting OIDC config into the connection string for convenience, or older examples that predate this restriction.
Related errors
- authMechanism requires an authSource of '$external
- Cannot have undefined values in key value pairs
- Host ' ' is not valid for OIDC authentication with…
- The ' ' option cannot be used with the ' ' option
- All values of tls/ssl must be the same.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/03516672c8eb9e81.
Report an issue: GitHub.
Appendix: source
Thrown at src/connection_string.ts:322
}
const objectOptions = new CaseInsensitiveMap<unknown>(
Object.entries(options).filter(([, v]) => v != null)
);
// Validate options that can only be provided by one of uri or object
if (urlOptions.has('serverApi')) {
throw new MongoParseError(
'URI cannot contain `serverApi`, it can only be passed to the client'
);
}
const uriMechanismProperties = urlOptions.get('authMechanismProperties');
if (uriMechanismProperties) {
for (const property of uriMechanismProperties) {
if (/(^|,)ALLOWED_HOSTS:/.test(property as string)) {
throw new MongoParseError(
'Auth mechanism property ALLOWED_HOSTS is not allowed in the connection string.'
);
}
}
}
if (objectOptions.has('loadBalanced')) {
throw new MongoParseError('loadBalanced is only a valid option in the URI');
}
// All option collection
const allProvidedOptions = new CaseInsensitiveMap<unknown[]>();
const allProvidedKeys = new Set<string>([...urlOptions.keys(), ...objectOptions.keys()]);
for (const key of allProvidedKeys) {
const values = [];View on GitHub (pinned to dce7939f86)