{"record":{"id":"a6aab0acf4c2cad1","repo":"redis/node-redis","slug":"session-secret-environment-variable-must-be-set","errorCode":null,"errorMessage":"SESSION_SECRET environment variable must be set","messagePattern":"SESSION_SECRET environment variable must be set","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/entraid/samples/auth-code-pkce/index.ts","lineNumber":9,"sourceCode":"import express, { Request, Response } from 'express';\nimport session from 'express-session';\nimport dotenv from 'dotenv';\nimport { DEFAULT_TOKEN_MANAGER_CONFIG, EntraIdCredentialsProviderFactory } from '../../lib/entra-id-credentials-provider-factory';\n\ndotenv.config();\n\nif (!process.env.SESSION_SECRET) {\n  throw new Error('SESSION_SECRET environment variable must be set');\n}\n\ninterface PKCESession extends session.Session {\n  pkceCodes?: {\n    verifier: string;\n    challenge: string;\n    challengeMethod: string;\n  };\n}\n\ninterface AuthRequest extends Request {\n  session: PKCESession;\n}\n\nconst app = express();\n\nconst sessionConfig = {\n  secret: process.env.SESSION_SECRET,","sourceCodeStart":1,"sourceCodeEnd":27,"githubUrl":"https://github.com/redis/node-redis/blob/90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58/packages/entraid/samples/auth-code-pkce/index.ts#L1-L27","documentation":"The `auth-code-pkce` sample boots an Express app with `express-session`, which requires a signing secret; the sample refuses to start if `SESSION_SECRET` is unset. It is a startup guard in the sample entry, not in the published library.","triggerScenarios":"Running `packages/entraid/samples/auth-code-pkce` without `SESSION_SECRET` in the environment / `.env`. Throws at module load, before the server listens.","commonSituations":"Forgot to copy/edit `.env`; CI/container missing the env var; cloned the sample and ran it as-is.","solutions":["Create `.env` in the sample with `SESSION_SECRET=<long-random-string>`.","Export `SESSION_SECRET` in your shell/container environment before launch.","Use a secret manager / `.env.example` to template the value."],"exampleFix":"# .env (before: missing)\n# after\nSESSION_SECRET=replace-with-a-long-random-value","handlingStrategy":"validation","validationCode":"function requireEnv(name: string): string {\n  const v = process.env[name];\n  if (!v) throw new Error(`${name} environment variable must be set`);\n  return v;\n}\nconst SESSION_SECRET = requireEnv('SESSION_SECRET');","typeGuard":"function hasEnv(name: string): boolean { return Boolean(process.env[name]); }","tryCatchPattern":null,"preventionTips":["Provide a `.env.example` and document required variables.","Fail fast at startup for missing secrets in all environments."],"tags":["entraid","sample","environment","session","startup"],"backgroundTag":null,"analyzedSha":"90fd0652bc3f2a0a1b2f79fa9096b02a86b0ac58","analyzedAt":"2026-08-11T15:37:21.243Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}