{"record":{"id":"8c6fc938af348369","repo":"redis/node-redis","slug":"msal-client-id-and-msal-tenant-id-environment-vari","errorCode":null,"errorMessage":"MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables must be set","messagePattern":"MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables must be set","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/entraid/samples/auth-code-pkce/index.ts","lineNumber":41,"sourceCode":"\nconst app = express();\n\nconst sessionConfig = {\n  secret: process.env.SESSION_SECRET,\n  resave: false,\n  saveUninitialized: false,\n  cookie: {\n    secure: process.env.NODE_ENV === 'production', // Only use secure in production\n    httpOnly: true,\n    sameSite: 'lax',\n    maxAge: 3600000 // 1 hour\n  }\n} as const;\n\napp.use(session(sessionConfig));\n\nif (!process.env.MSAL_CLIENT_ID || !process.env.MSAL_TENANT_ID) {\n  throw new Error('MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables must be set');\n}\n\n// Initialize MSAL provider with authorization code PKCE flow\nconst {\n  getPKCECodes,\n  createCredentialsProvider,\n  getAuthCodeUrl\n} = EntraIdCredentialsProviderFactory.createForAuthorizationCodeWithPKCE({\n  clientId: process.env.MSAL_CLIENT_ID,\n  redirectUri: process.env.REDIRECT_URI || 'http://localhost:3000/redirect',\n  authorityConfig: { type: 'multi-tenant', tenantId: process.env.MSAL_TENANT_ID },\n  tokenManagerConfig: DEFAULT_TOKEN_MANAGER_CONFIG\n});\n\napp.get('/login', async (req: AuthRequest, res: Response) => {\n  try {\n    // Generate PKCE Codes before starting the authorization flow\n    const pkceCodes = await getPKCECodes();","sourceCodeStart":23,"sourceCodeEnd":59,"githubUrl":"https://github.com/redis/node-redis/blob/90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58/packages/entraid/samples/auth-code-pkce/index.ts#L23-L59","documentation":"The `auth-code-pkce` sample builds an MSAL authorization-code-with-PKCE provider that needs an app registration; it refuses to start unless both `MSAL_CLIENT_ID` and `MSAL_TENANT_ID` are present. Startup guard in the sample entry, after the session check.","triggerScenarios":"Running the `auth-code-pkce` sample without `MSAL_CLIENT_ID` and/or `MSAL_TENANT_ID` set. Throws at module load before MSAL is initialized.","commonSituations":"No Entra ID app registration created yet; registration exists but env vars not populated; `.env` incomplete; wrong env in container.","solutions":["Register an application in Entra ID (Azure portal) and copy its Application (client) ID and Directory (tenant) ID.","Add `MSAL_CLIENT_ID` and `MSAL_TENANT_ID` to the sample `.env`.","Restart the sample after setting the variables."],"exampleFix":"# .env (before: missing)\n# after\nMSAL_CLIENT_ID=00000000-0000-0000-0000-000000000000\nMSAL_TENANT_ID=00000000-0000-0000-0000-000000000000","handlingStrategy":"validation","validationCode":"function requireEnvs(names: string[]): Record<string, string> {\n  const out: Record<string, string> = {};\n  for (const n of names) {\n    const v = process.env[n];\n    if (!v) throw new Error(`${names.join(' and ')} environment variables must be set`);\n    out[n] = v;\n  }\n  return out;\n}\nconst { MSAL_CLIENT_ID, MSAL_TENANT_ID } = requireEnvs(['MSAL_CLIENT_ID', 'MSAL_TENANT_ID']);","typeGuard":"function hasMsalEnv(): boolean {\n  return Boolean(process.env.MSAL_CLIENT_ID) && Boolean(process.env.MSAL_TENANT_ID);\n}","tryCatchPattern":null,"preventionTips":["Create the Entra ID app registration before first run.","Keep all required env vars in a version-controlled `.env.example`."],"tags":["entraid","sample","environment","msal","app-registration","startup"],"backgroundTag":null,"analyzedSha":"90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58","analyzedAt":"2026-08-11T15:37:21.243Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}