{"record":{"id":"9283ac9ba7b763da","repo":"redis/node-redis","slug":"invalid-authority-configuration","errorCode":null,"errorMessage":"Invalid authority configuration","messagePattern":"Invalid authority configuration","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/entraid/lib/entra-id-credentials-provider-factory.ts","lineNumber":258,"sourceCode":"        return new EntraidCredentialsProvider(tm, idp, {\n          onReAuthenticationError: params.onReAuthenticationError,\n          credentialsMapper: params.credentialsMapper ?? DEFAULT_CREDENTIALS_MAPPER,\n          onRetryableError: params.onRetryableError\n        });\n      }\n    };\n  }\n\n  static getAuthority(config: AuthorityConfig): string {\n    switch (config.type) {\n      case 'multi-tenant':\n        return `https://login.microsoftonline.com/${config.tenantId}`;\n      case 'custom':\n        return config.authorityUrl;\n      case 'default':\n        return 'https://login.microsoftonline.com/common';\n      default:\n        throw new Error('Invalid authority configuration');\n    }\n  }\n\n}\n\nexport const REDIS_SCOPE_DEFAULT = 'https://redis.azure.com/.default';\nexport const REDIS_SCOPE = 'https://redis.azure.com'\n\nexport type AuthorityConfig =\n  | { type: 'multi-tenant'; tenantId: string }\n  | { type: 'custom'; authorityUrl: string }\n  | { type: 'default' };\n\nexport type PKCEParams = {\n  code: string;\n  verifier: string;\n  clientInfo?: string;\n}","sourceCodeStart":240,"sourceCodeEnd":276,"githubUrl":"https://github.com/redis/node-redis/blob/90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58/packages/entraid/lib/entra-id-credentials-provider-factory.ts#L240-L276","documentation":"`EntraIdCredentialsProviderFactory.getAuthority()` switches on `config.type` and only knows `'multi-tenant'`, `'custom'`, and `'default'` (the `AuthorityConfig` discriminated union). Any other value hits the `default` branch and throws 'Invalid authority configuration'. TypeScript narrows the union so this is primarily a runtime/JSDoc-default concern when config arrives untyped.","triggerScenarios":"Passing an `AuthorityConfig` whose `type` is not one of the three valid literals, e.g. from parsed JSON/env where the field is missing, misspelled ('multitenant'), or lowercased differently.","commonSituations":"Loading authority config from environment/JSON without validation; typo in the discriminator; version skew where a caller sends an old/new type string.","solutions":["Use exactly one of: `{ type: 'multi-tenant', tenantId }`, `{ type: 'custom', authorityUrl }`, or `{ type: 'default' }`.","Validate/normalize the `type` string before constructing the config (case-sensitive).","Type the config source as `AuthorityConfig` so the compiler rejects bad values."],"exampleFix":"// before\ngetAuthority({ type: 'multitenant', tenantId: 'xxx' }); // typo\n// after\ngetAuthority({ type: 'multi-tenant', tenantId: 'xxx' });","handlingStrategy":"type-guard","validationCode":"function normalizeAuthority(c: unknown) {\n  if (c && typeof c === 'object' && 'type' in c) {\n    const t = (c as { type: string }).type;\n    if (t === 'multi-tenant' || t === 'custom' || t === 'default') return c;\n  }\n  throw new Error(`Unknown authority type; expected multi-tenant|custom|default`);\n}","typeGuard":"function isAuthorityConfig(c: unknown): c is { type: 'multi-tenant'; tenantId: string } | { type: 'custom'; authorityUrl: string } | { type: 'default' } {\n  if (!c || typeof c !== 'object') return false;\n  const t = (c as { type?: unknown }).type;\n  return t === 'multi-tenant' || t === 'custom' || t === 'default';\n}","tryCatchPattern":"try { EntraIdCredentialsProviderFactory.getAuthority(cfg); }\ncatch (e) {\n  if (String(e).includes('Invalid authority configuration')) {\n    cfg = { type: 'default' as const };\n    EntraIdCredentialsProviderFactory.getAuthority(cfg);\n  } else throw e;\n}","preventionTips":["Type config sources as AuthorityConfig so the compiler rejects bad discriminators.","Validate config loaded from env/JSON against the union before use."],"tags":["entraid","configuration","authority","discriminated-union"],"backgroundTag":null,"analyzedSha":"90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58","analyzedAt":"2026-08-11T15:37:21.243Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}