{"record":{"id":"25287c78df073729","repo":"mongodb/node-mongodb-native","slug":"no-workflow-provided-to-the-oidc-auth-provider","errorCode":null,"errorMessage":"No workflow provided to the OIDC auth provider.","messagePattern":"No workflow provided to the OIDC auth provider\\.","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"critical","filePath":"src/cmap/auth/mongodb_oidc.ts","lineNumber":141,"sourceCode":"export const OIDC_WORKFLOWS: Map<EnvironmentName, () => Workflow> = new Map();\nOIDC_WORKFLOWS.set('test', () => new AutomatedCallbackWorkflow(new TokenCache(), testCallback));\nOIDC_WORKFLOWS.set('azure', () => new AutomatedCallbackWorkflow(new TokenCache(), azureCallback));\nOIDC_WORKFLOWS.set('gcp', () => new AutomatedCallbackWorkflow(new TokenCache(), gcpCallback));\nOIDC_WORKFLOWS.set('k8s', () => new AutomatedCallbackWorkflow(new TokenCache(), k8sCallback));\n\n/**\n * OIDC auth provider.\n */\nexport class MongoDBOIDC extends AuthProvider {\n  workflow: Workflow;\n\n  /**\n   * Instantiate the auth provider.\n   */\n  constructor(workflow?: Workflow) {\n    super();\n    if (!workflow) {\n      throw new MongoInvalidArgumentError('No workflow provided to the OIDC auth provider.');\n    }\n    this.workflow = workflow;\n  }\n\n  /**\n   * Authenticate using OIDC\n   */\n  override async auth(authContext: AuthContext): Promise<void> {\n    const { connection, reauthenticating, response } = authContext;\n    if (response?.speculativeAuthenticate?.done && !reauthenticating) {\n      return;\n    }\n    const credentials = getCredentials(authContext);\n    if (reauthenticating) {\n      await this.workflow.reauthenticate(connection, credentials);\n    } else {\n      await this.workflow.execute(connection, credentials, response);\n    }","sourceCodeStart":123,"sourceCodeEnd":159,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc.ts#L123-L159","documentation":"Thrown by the MongoDBOIDC auth provider constructor (mongodb_oidc.ts:141) when no workflow argument is supplied. The driver normally selects an OIDC workflow from OIDC_WORKFLOWS keyed by ENVIRONMENT (test/azure/gcp/k8s); a missing workflow means the environment was unrecognized or the provider was instantiated directly without one. Raised as MongoInvalidArgumentError.","triggerScenarios":"Specifying authMechanismProperties.ENVIRONMENT with a value outside {test, azure, gcp, k8s}, or programmatically constructing new MongoDBOIDC() without passing a workflow. Also possible if a driver version predates the environment you specified.","commonSituations":"Typo or wrong case in ENVIRONMENT (e.g., 'GCP', 'gcps', 'aws'). Using an older driver that does not yet register the environment you need. Forking the driver and forgetting to register a custom workflow in OIDC_WORKFLOWS.","solutions":["Use one of the supported ENVIRONMENT values exactly: test, azure, gcp, or k8s","For custom OIDC, supply your own workflow/callback via code rather than a named environment","Upgrade the driver to a version that supports your target environment","Check the ENVIRONMENT value for typos and case sensitivity"],"exampleFix":"// before\nconst uri =\n  'mongodb://host/?authMechanism=MONGODB-OIDC&authMechanismProperties=ENVIRONMENT:GCP';\n\n// after\nconst uri =\n  'mongodb://host/?authMechanism=MONGODB-OIDC&authMechanismProperties=ENVIRONMENT:gcp,TOKEN_RESOURCE:<audience>';","handlingStrategy":"validation","validationCode":"const SUPPORTED = new Set(['test', 'azure', 'gcp', 'k8s']);\nconst env = clientOptions.auth?.mechanismProperties?.ENVIRONMENT;\nif (env !== undefined && !SUPPORTED.has(env)) {\n  throw new Error(`Unsupported OIDC ENVIRONMENT '${env}'. Supported: ${[...SUPPORTED].join(', ')}`);\n}","typeGuard":"function isSupportedOidcEnv(env: unknown): env is 'test' | 'azure' | 'gcp' | 'k8s' {\n  return typeof env === 'string' && ['test', 'azure', 'gcp', 'k8s'].includes(env);\n}","tryCatchPattern":null,"preventionTips":["Validate the ENVIRONMENT value against the supported set at config-load time","Treat ENVIRONMENT case-sensitively (lowercase only)","Upgrade the driver when adopting a new OIDC environment"],"tags":["oidc","configuration","authentication","internal"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}