Skip to content

feat(NODE-7830): add srvAllowedHostsSuffix and srvHostValidator options - #5065

Draft
PavelSafronov wants to merge 3 commits into
mainfrom
node7830-node7610-dns
Draft

PavelSafronov wants to merge 3 commits into
mainfrom
node7830-node7610-dns

Conversation

@PavelSafronov

@PavelSafronov PavelSafronov commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Description

Summary of Changes

Add two new ways to customize DNS resolution: srvAllowedHostsSuffix and srvHostValidator.

We are also modifying the behavior of the Driver for all mongodb+srv users: SRV host names are now normalized before comparison (lowercased, trailing dot removed, international names converted to xn-- form). As a result, a connection string whose SRV host name differs in case from the host names DNS returns, such as mongodb+srv://TEST1.TEST.BUILD.10GEN.CC, now passes SRV verification instead of failing with "Server record does not share hostname with parent URI".

Notes for Reviewers

This implements the following DRIVERS tickets:

  1. DRIVERS-3329 - DRIVERS-3329: Configurable DNS domain validation for SRV records specifications#1950
  2. DRIVERS-3632 - DRIVERS-3632 Introduce Custom Callback logic in Configurable DNS specifications#1980
  3. DRIVERS-3664 - DRIVERS-3664 Configurable DNS domain validation for SRV records: clarifications specifications#1989

The specifications include this SHOULD step that we skip:

  1. Drivers SHOULD raise an error if the resulting value is a public suffix, per the algorithm in
    Public Suffix List, unless the value is in the aforementioned list
    of valid names.

This is a SHOULD, so Node/Java/C# do not implement the Public Suffix List (PSL), only Python has added PSL support to their driver so far.

DRIVERS-3664 is open to make some changes to the relevant specs, current work should not be merged before 3664 is reviewed and merged.

For this work, we aren't pulling in all the specifications changes from main, they will be done with their respective NODE tickets:

An unrelated test fix adds some entries to test/mongodb_bundled.ts. Once we complete NODE-7850, these missing entries will cause a build failure, so in the future it won't be possible to get into this state.

Host name conversion follows the WHATWG URL Standard's domain parser; the spec allows drivers to choose their IDNA processing standard. The URL Standard was updated in June 2026 to return ASCII names lowercased even when their xn-- labels are not valid A-labels, but Node.js only picked this up in 24.20.0 (nodejs/node#64790, Ada 4.0.0), so earlier Node.js versions reject such names in url.domainToASCII. To behave the same on every Node.js version, and to keep accepting host names that main accepts today, we lowercase ASCII names ourselves instead of relying on url.domainToASCII.

Release Highlight

Configurable SRV host validation

This release adds two new methods of validating DNS:

  1. srvAllowedHostsSuffix - A host name suffix that every host returned by the SRV lookup must end with. This option can be configured on the client or the connection string.
  2. srvHostValidator - A synchronous function that decides whether a host returned by the SRV lookup may be used. This option can only be configured on the client. This function must accept a string and has to return a boolean; returning anything else, including the Promise returned by an async function, will result in an error.

Warning

Modifying the default SRV domain name validation can create vulnerabilities.

SRV host names are now compared in a normalized form (case-insensitively, without a trailing dot, and with internationalized names in xn-- form). Connection strings whose SRV host name differs in case from the host names returned by DNS, such as mongodb+srv://TEST1.TEST.BUILD.10GEN.CC, previously failed SRV verification and now connect.

Double check the following

  • Lint is passing (npm run check:lint)
  • Self-review completed using the steps outlined here
  • PR title follows the correct format: type(NODE-xxxx)[!]: description
    • Example: feat(NODE-1234)!: rewriting everything in coffeescript
  • Changes are covered by tests
  • New TODOs have a related JIRA ticket

@PavelSafronov PavelSafronov changed the title feat(NODE-7830): Introduce Custom Callback logic in Configurable DNS feat(NODE-7830): add srvAllowedHostsSuffix and srvHostValidator options Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant