Checking if string is an ObjectId in MongoDB using Mongoose


Using mongoose.Types.ObjectId.isValid to check if an ObjecId is valid and not a random string will return TRUE for any string of 12 bytes, this could be catastrophic.

Screenshot 2020-07-08 at 6.18.15 PM.png


To solve this, I suggest you create a new ObjectId using the string, then compare the results. ObjectId will always return thesame value if its a true

Screenshot 2020-07-08 at 6.25.38 PM.png

No Comments Yet