{"record":{"id":"c307436a2e8c6c94","repo":"mongodb/node-mongodb-native","slug":"malformed-response-body-missing-field-expires-i","errorCode":null,"errorMessage":"Malformed response body - missing field `expires_in`.","messagePattern":"Malformed response body - missing field `expires_in`\\.","errorType":"exception","errorClass":"MongoCryptAzureKMSRequestError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/providers/azure.ts","lineNumber":90,"sourceCode":"    try {\n      return JSON.parse(rawBody);\n    } catch {\n      throw new MongoCryptAzureKMSRequestError('Malformed JSON body in GET request.');\n    }\n  })();\n\n  if (status !== 200) {\n    throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);\n  }\n\n  if (!body.access_token) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - missing field `access_token`.'\n    );\n  }\n\n  if (!body.expires_in) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - missing field `expires_in`.'\n    );\n  }\n\n  const expiresInMS = Number(body.expires_in) * 1000;\n  if (Number.isNaN(expiresInMS)) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - unable to parse int from `expires_in` field.'\n    );\n  }\n\n  return {\n    accessToken: body.access_token,\n    expiresOnTimestamp: Date.now() + expiresInMS\n  };\n}\n\n/**","sourceCodeStart":72,"sourceCodeEnd":108,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/providers/azure.ts#L72-L108","documentation":"Thrown when the Azure IMDS JSON response lacks the expires_in field. The driver uses expires_in to compute the token cache expiry; without it the token cannot be safely cached. MongoCryptAzureKMSRequestError.","triggerScenarios":"An Azure endpoint (or a test/proxy stand-in) returning a JSON body with access_token but omitting expires_in; a custom AzureKMSRequestOptions.url in tests pointing at a mock that returns an incomplete token object.","commonSituations":"Using a mock/stub IMDS endpoint in CI that returns { access_token } only; Azure regional anomaly returning a truncated body; a man-in-the-middle proxy stripping fields.","solutions":["If testing, ensure the mock IMDS endpoint returns both access_token (string) and expires_in (seconds, number).","If in production Azure, treat this as an Azure platform issue and retry; if persistent, open an Azure support ticket.","Avoid overriding the Azure KMS request URL outside of tests; the default IMDS endpoint returns both fields."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"function assertAzureTokenShape(body) {\n  if (typeof body.access_token !== 'string') throw new Error('missing access_token');\n  if (body.expires_in == null) throw new Error('missing expires_in');\n  if (Number.isNaN(Number(body.expires_in))) throw new Error('expires_in not numeric');\n}","typeGuard":"function isAzureTokenResponse(b: unknown): b is { access_token: string; expires_in: number } {\n  return typeof b === 'object' && b !== null &&\n    typeof (b as any).access_token === 'string' &&\n    typeof (b as any).expires_in !== 'undefined';\n}","tryCatchPattern":null,"preventionTips":["Only override the Azure KMS URL in tests, and ensure mocks return access_token + expires_in.","Do not run production against a custom IMDS proxy."],"tags":["csfle","azure","kms","testing"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}