{"record":{"id":"2def4edc94f53eca","repo":"mongodb/node-mongodb-native","slug":"attempted-to-get-idp-information-when-none-exists","errorCode":null,"errorMessage":"Attempted to get IDP information when none exists.","messagePattern":"Attempted to get IDP information when none exists\\.","errorType":"exception","errorClass":"MongoOIDCError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_oidc/token_cache.ts","lineNumber":41,"sourceCode":"  }\n\n  getAccessToken(): string {\n    if (!this.accessToken) {\n      throw new MongoOIDCError('Attempted to get an access token when none exists.');\n    }\n    return this.accessToken;\n  }\n\n  getRefreshToken(): string {\n    if (!this.refreshToken) {\n      throw new MongoOIDCError('Attempted to get a refresh token when none exists.');\n    }\n    return this.refreshToken;\n  }\n\n  getIdpInfo(): IdPInfo {\n    if (!this.idpInfo) {\n      throw new MongoOIDCError('Attempted to get IDP information when none exists.');\n    }\n    return this.idpInfo;\n  }\n\n  put(response: OIDCResponse, idpInfo?: IdPInfo) {\n    this.accessToken = response.accessToken;\n    this.refreshToken = response.refreshToken;\n    this.expiresInSeconds = response.expiresInSeconds;\n    if (idpInfo) {\n      this.idpInfo = idpInfo;\n    }\n  }\n\n  removeAccessToken() {\n    this.accessToken = undefined;\n  }\n\n  removeRefreshToken() {","sourceCodeStart":23,"sourceCodeEnd":59,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc/token_cache.ts#L23-L59","documentation":"Internal invariant of TokenCache (token_cache.ts:41): getIdpInfo() was called while idpInfo is undefined. The human workflow checks hasIdpInfo / passes idpInfo explicitly when calling getIdpInfo, so this should be unreachable from the public API. Reaching it indicates a driver bug or direct misuse of the @internal TokenCache.","triggerScenarios":"Calling the internal TokenCache.getIdpInfo() without first checking hasIdpInfo; or a regression where a workflow reads idpInfo before it was put into the cache via cache.put(response, idpInfo).","commonSituations":"Forked/monkeypatched auth providers bypassing the hasIdpInfo guard. A driver regression where getIdpInfo is reached before the two-step SASL IdPInfo response is cached.","solutions":["File a driver bug if reached via the public API with reproduction steps","With internal APIs, check cache.hasIdpInfo before cache.getIdpInfo()","Upgrade the driver to pick up any fixed regression"],"exampleFix":"// before\nconst idp = cache.getIdpInfo();\n\n// after\nconst idp = cache.hasIdpInfo ? cache.getIdpInfo() : undefined;","handlingStrategy":"type-guard","validationCode":null,"typeGuard":"function getIdpInfoSafe(cache: TokenCache): IdPInfo | undefined {\n  return cache.hasIdpInfo ? cache.getIdpInfo() : undefined;\n}","tryCatchPattern":null,"preventionTips":["Rely on the public API; the human workflow passes idpInfo explicitly when needed","In forks, check hasIdpInfo before getIdpInfo","Pin a stable driver version and upgrade deliberately"],"tags":["oidc","internal","invariant","token-cache"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}