mongodb/node-mongodb-native · error · MongoInvalidArgumentError
Auth mechanism property ALLOWED_HOSTS must be an array of…
Error message
Auth mechanism property ALLOWED_HOSTS must be an array of strings.
What it means
Thrown by MongoCredentials.validate() when the MONGODB-OIDC ALLOWED_HOSTS property is present but is not an Array. ALLOWED_HOSTS restricts which hostnames may receive the OIDC token (SSRF protection) and must be an array of strings; a non-array value is rejected before any network call.
Solutions
- Provide ALLOWED_HOSTS as an array of strings, e.g. ['localhost','*.mongodb.net'].
- If overriding defaults, ensure the value is literally an Array in the JS options object.
- Omit ALLOWED_HOSTS entirely to use DEFAULT_ALLOWED_HOSTS if you do not need custom hosts.
Example fix
// before
mechanismProperties: { ENVIRONMENT:'test', ALLOWED_HOSTS: 'localhost' }
// after
mechanismProperties: { ENVIRONMENT:'test', ALLOWED_HOSTS: ['localhost'] } Defensive patterns
Strategy: type-guard
Validate before calling
function assertAllowedHosts(props) {
if ('ALLOWED_HOSTS' in props && !Array.isArray(props.ALLOWED_HOSTS)) {
throw new Error('ALLOWED_HOSTS must be an array.');
}
} Type guard
function isStringArray(v): v is string[] {
return Array.isArray(v) && v.every(x => typeof x === 'string');
} Prevention
- Always pass ALLOWED_HOSTS as an array literal.
- Omit the property to inherit DEFAULT_ALLOWED_HOSTS unless you need custom hosts.
- Add a runtime guard in your config layer.
When it happens
Trigger: Setting authMechanismProperties.ALLOWED_HOSTS to a string, object, number, or any non-array value while using MONGODB-OIDC. Fires in validate() at line 240.
Common situations: Passing a single host as a string (e.g. 'localhost') instead of ['localhost']. Mis-formatting the connection-string authMechanismProperties (ALLOWED_HOSTS:localhost instead of ALLOWED_HOSTS:localhost,127.0.0.1).
Related errors
- Currently only a ENVIRONMENT in
- AuthContext must provide credentials.
- Either a ENVIRONMENT, OIDC_CALLBACK, or OIDC_HUMAN_CALLBACK…
- Invalid CANONICALIZE_HOST_NAME value
- No password is allowed in ENVIRONMENT
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/509e517563ee3feb.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongo_credentials.ts:240
','
)} is supported for mechanism '${this.mechanism}'.`
);
}
if (
!this.mechanismProperties.ENVIRONMENT &&
!this.mechanismProperties.OIDC_CALLBACK &&
!this.mechanismProperties.OIDC_HUMAN_CALLBACK
) {
throw new MongoInvalidArgumentError(
`Either a ENVIRONMENT, OIDC_CALLBACK, or OIDC_HUMAN_CALLBACK must be specified for mechanism '${this.mechanism}'.`
);
}
if (this.mechanismProperties.ALLOWED_HOSTS) {
const hosts = this.mechanismProperties.ALLOWED_HOSTS;
if (!Array.isArray(hosts)) {
throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);
}
for (const host of hosts) {
if (typeof host !== 'string') {
throw new MongoInvalidArgumentError(ALLOWED_HOSTS_ERROR);
}
}
}
}
if (AUTH_MECHS_AUTH_SRC_EXTERNAL.has(this.mechanism)) {
if (this.source != null && this.source !== '$external') {
// TODO(NODE-3485): Replace this with a MongoAuthValidationError
throw new MongoAPIError(
`Invalid source '${this.source}' for mechanism '${this.mechanism}' specified.`
);
}
}
View on GitHub (pinned to dce7939f86)