{"record":{"id":"1fc6dcc0561ae231","repo":"mongodb/node-mongodb-native","slug":"reauthentication-already-in-progress","errorCode":null,"errorMessage":"Reauthentication already in progress.","messagePattern":"Reauthentication already in progress\\.","errorType":"exception","errorClass":"MongoRuntimeError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/auth_provider.ts","lineNumber":68,"sourceCode":"    _authContext: AuthContext\n  ): Promise<HandshakeDocument> {\n    return handshakeDoc;\n  }\n\n  /**\n   * Authenticate\n   *\n   * @param context - A shared context for authentication flow\n   */\n  abstract auth(context: AuthContext): Promise<void>;\n\n  /**\n   * Reauthenticate.\n   * @param context - The shared auth context.\n   */\n  async reauth(context: AuthContext): Promise<void> {\n    if (context.reauthenticating) {\n      throw new MongoRuntimeError('Reauthentication already in progress.');\n    }\n    try {\n      context.reauthenticating = true;\n      await this.auth(context);\n    } finally {\n      context.reauthenticating = false;\n    }\n  }\n}\n","sourceCodeStart":50,"sourceCodeEnd":78,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/auth_provider.ts#L50-L78","documentation":"Thrown by AuthProvider.reauth when context.reauthenticating is already true — i.e. a re-authentication flow was started and a second one was triggered before the first finished. The driver re-authenticates (e.g. for OIDC token refresh, AWS session expiry, or after a 391 'Reauthenticate' server error) and this guard prevents overlapping flows on the same connection. It is a MongoRuntimeError.","triggerScenarios":"Two concurrent operations on a connection both receive a re-authenticate signal and attempt reauth simultaneously; an auth provider's reauth recursively calls reauth; manual invocation of reauth while the SDAM monitor is also re-authenticating.","commonSituations":"OIDC tokens expiring under high concurrency where multiple connections reauth at once; AWS temporary credentials expiring mid-operation; a server 391 response arriving during an in-flight reauth; driver bug causing double reauth dispatch.","solutions":["Let the driver manage re-authentication automatically (do not call internal auth APIs); ensure only one reauth is in flight per connection.","For OIDC, implement the token callback to be fast and cached so concurrent reauth attempts resolve quickly and don't pile up.","If using short-lived credentials, give them a TTL comfortably longer than operation latency to avoid frequent reauth.","Upgrade the driver — reauth concurrency has been refined across releases; a double-dispatch may be a fixed bug."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":["Let the driver handle re-authentication; do not invoke internal auth methods concurrently.","Make OIDC token callbacks fast and cached to avoid reauth pile-ups.","Use credentials with TTL comfortably longer than your longest operation."],"tags":["auth","oidc","authentication","concurrency","internal"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}