{"record":{"id":"2db32a57c0accd16","repo":"redis/node-redis","slug":"session-secret-environment-variable-must-be-set-2db32a","errorCode":null,"errorMessage":"SESSION_SECRET environment variable must be set","messagePattern":"SESSION_SECRET environment variable must be set","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/entraid/samples/interactive-browser/index.ts","lineNumber":10,"sourceCode":"import express, { Request, Response } from 'express';\nimport session from 'express-session';\nimport dotenv from 'dotenv';\nimport { DEFAULT_TOKEN_MANAGER_CONFIG, EntraIdCredentialsProviderFactory } from '../../lib/entra-id-credentials-provider-factory';\nimport { InteractiveBrowserCredential } from '@azure/identity';\n\ndotenv.config();\n\nif (!process.env.SESSION_SECRET) {\n  throw new Error('SESSION_SECRET environment variable must be set');\n}\n\nconst app = express();\n\nconst sessionConfig = {\n  secret: process.env.SESSION_SECRET,\n  resave: false,\n  saveUninitialized: false,\n  cookie: {\n    secure: process.env.NODE_ENV === 'production', // Only use secure in production\n    httpOnly: true,\n    sameSite: 'lax',\n    maxAge: 3600000 // 1 hour\n  }\n} as const;\n\napp.use(session(sessionConfig));\n","sourceCodeStart":1,"sourceCodeEnd":28,"githubUrl":"https://github.com/redis/node-redis/blob/90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58/packages/entraid/samples/interactive-browser/index.ts#L1-L28","documentation":"The `interactive-browser` sample uses the same Express + express-session bootstrap and applies the identical `SESSION_SECRET` startup guard in its own entry file. It refuses to boot without the secret, independent of the auth-code-pkce sample.","triggerScenarios":"Running `packages/entraid/samples/interactive-browser` without `SESSION_SECRET` in the environment / `.env`. Throws at module load, before `InteractiveBrowserCredential` is constructed.","commonSituations":"Missing `.env` for this sample specifically; container/CI without the var; copied the sample folder without its env template.","solutions":["Add `SESSION_SECRET=<long-random-string>` to the sample's `.env`.","Export `SESSION_SECRET` in the runtime environment.","Generate a strong random secret (e.g. `openssl rand -hex 32`)."],"exampleFix":"# .env (before: missing)\n# after\nSESSION_SECRET=$(openssl rand -hex 32)","handlingStrategy":"validation","validationCode":"function requireEnv(name: string): string {\n  const v = process.env[name];\n  if (!v) throw new Error(`${name} environment variable must be set`);\n  return v;\n}\nconst SESSION_SECRET = requireEnv('SESSION_SECRET');","typeGuard":"function hasEnv(name: string): boolean { return Boolean(process.env[name]); }","tryCatchPattern":null,"preventionTips":["Give each sample its own `.env` derived from `.env.example`.","Generate strong random secrets with `openssl rand -hex 32`."],"tags":["entraid","sample","environment","session","startup","interactive-browser"],"backgroundTag":null,"analyzedSha":"90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58","analyzedAt":"2026-08-11T15:37:21.243Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}