{"record":{"id":"ab063953e8f7eadd","repo":"mongodb/node-mongodb-native","slug":"attempted-to-get-an-access-token-when-none-exists","errorCode":null,"errorMessage":"Attempted to get an access token when none exists.","messagePattern":"Attempted to get an access token when none exists\\.","errorType":"exception","errorClass":"MongoOIDCError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_oidc/token_cache.ts","lineNumber":27,"sourceCode":"  private refreshToken?: string;\n  private idpInfo?: IdPInfo;\n  private expiresInSeconds?: number;\n\n  get hasAccessToken(): boolean {\n    return !!this.accessToken;\n  }\n\n  get hasRefreshToken(): boolean {\n    return !!this.refreshToken;\n  }\n\n  get hasIdpInfo(): boolean {\n    return !!this.idpInfo;\n  }\n\n  getAccessToken(): string {\n    if (!this.accessToken) {\n      throw new MongoOIDCError('Attempted to get an access token when none exists.');\n    }\n    return this.accessToken;\n  }\n\n  getRefreshToken(): string {\n    if (!this.refreshToken) {\n      throw new MongoOIDCError('Attempted to get a refresh token when none exists.');\n    }\n    return this.refreshToken;\n  }\n\n  getIdpInfo(): IdPInfo {\n    if (!this.idpInfo) {\n      throw new MongoOIDCError('Attempted to get IDP information when none exists.');\n    }\n    return this.idpInfo;\n  }\n","sourceCodeStart":9,"sourceCodeEnd":45,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc/token_cache.ts#L9-L45","documentation":"Internal invariant of TokenCache (token_cache.ts:27): getAccessToken() was called while accessToken is undefined. The OIDC workflows always gate getAccessToken() behind hasAccessToken, so a normal public-API call path should never reach this throw. Reaching it indicates a regression in cache-state management inside the driver or direct misuse of the @internal TokenCache API. It surfaces as MongoDriverError (the local MongoOIDCError subclass extends MongoDriverError).","triggerScenarios":"Calling the internal TokenCache.getAccessToken() directly without first checking hasAccessToken; or a driver code path that calls getAccessToken() without its hasAccessToken guard (a bug). Not reachable through the documented public MongoClient API.","commonSituations":"Forking or monkeypatching the driver's auth providers and bypassing the hasAccessToken check. Hitting a driver regression where a workflow calls getAccessToken after removeAccessToken in an edge case.","solutions":["If reached via the public API, file a driver bug with a reproduction (the public workflows guard this)","If you use the internal TokenCache API directly, always check cache.hasAccessToken before cache.getAccessToken()","Upgrade to the latest driver version in case it is a fixed regression"],"exampleFix":"// before (internal misuse)\nconst token = cache.getAccessToken();\n\n// after\nconst token = cache.hasAccessToken ? cache.getAccessToken() : undefined;","handlingStrategy":"type-guard","validationCode":null,"typeGuard":"function getAccessTokenSafe(cache: TokenCache): string | undefined {\n  return cache.hasAccessToken ? cache.getAccessToken() : undefined;\n}","tryCatchPattern":null,"preventionTips":["Never call TokenCache getters directly; go through the public MongoClient API","If you touch internal cache APIs in a fork, always pair hasX/getX","Pin a known-good driver version and watch the changelog for OIDC workflow fixes"],"tags":["oidc","internal","invariant","token-cache"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}