mongodb/node-mongodb-native · error · MongoInvalidArgumentError

Auth mechanism property ALLOWED_HOSTS must be an array of…

Error message

Auth mechanism property ALLOWED_HOSTS must be an array of strings.

What it means

Thrown by MongoCredentials.validate() when the MONGODB-OIDC ALLOWED_HOSTS property is present but is not an Array. ALLOWED_HOSTS restricts which hostnames may receive the OIDC token (SSRF protection) and must be an array of strings; a non-array value is rejected before any network call.

Solutions

  1. Provide ALLOWED_HOSTS as an array of strings, e.g. ['localhost','*.mongodb.net'].
  2. If overriding defaults, ensure the value is literally an Array in the JS options object.
  3. Omit ALLOWED_HOSTS entirely to use DEFAULT_ALLOWED_HOSTS if you do not need custom hosts.

Example fix

// before
mechanismProperties: { ENVIRONMENT:'test', ALLOWED_HOSTS: 'localhost' }
// after
mechanismProperties: { ENVIRONMENT:'test', ALLOWED_HOSTS: ['localhost'] }
Defensive patterns

Strategy: type-guard

Validate before calling

function assertAllowedHosts(props) {
  if ('ALLOWED_HOSTS' in props && !Array.isArray(props.ALLOWED_HOSTS)) {
    throw new Error('ALLOWED_HOSTS must be an array.');
  }
}

Type guard

function isStringArray(v): v is string[] {
  return Array.isArray(v) && v.every(x => typeof x === 'string');
}

Prevention

When it happens

Trigger: Setting authMechanismProperties.ALLOWED_HOSTS to a string, object, number, or any non-array value while using MONGODB-OIDC. Fires in validate() at line 240.

Common situations: Passing a single host as a string (e.g. 'localhost') instead of ['localhost']. Mis-formatting the connection-string authMechanismProperties (ALLOWED_HOSTS:localhost instead of ALLOWED_HOSTS:localhost,127.0.0.1).

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/509e517563ee3feb. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/mongo_credentials.ts:240

            ','
          )} is supported for mechanism '${this.mechanism}'.`
        );
      }

      if (
        !this.mechanismProperties.ENVIRONMENT &&
        !this.mechanismProperties.OIDC_CALLBACK &&
        !this.mechanismProperties.OIDC_HUMAN_CALLBACK
      ) {
        throw new MongoInvalidArgumentError(
          `Either a ENVIRONMENT, OIDC_CALLBACK, or OIDC_HUMAN_CALLBACK must be specified for mechanism '${this.mechanism}'.`
        );
      }

      if (this.mechanismProperties.ALLOWED_HOSTS) {
        const hosts = this.mechanismProperties.ALLOWED_HOSTS;
        if (!Array.isArray(hosts)) {
          throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);
        }
        for (const host of hosts) {
          if (typeof host !== 'string') {
            throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);
          }
        }
      }
    }

    if (AUTH_MECHS_AUTH_SRC_EXTERNAL.has(this.mechanism)) {
      if (this.source != null && this.source !== '$external') {
        // TODO(NODE-3485): Replace this with a MongoAuthValidationError
        throw new MongoAPIError(
          `Invalid source '${this.source}' for mechanism '${this.mechanism}' specified.`
        );
      }
    }

View on GitHub (pinned to dce7939f86)