{"record":{"id":"c43eea4ecf8d22ba","repo":"mongodb/node-mongodb-native","slug":"oidc-callback-timed-out-after-human-timeout-ms-m","errorCode":null,"errorMessage":"OIDC callback timed out after ${HUMAN_TIMEOUT_MS}ms.","messagePattern":"OIDC callback timed out after (.+?)ms\\.","errorType":"exception","errorClass":"MongoOIDCError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_oidc/human_callback_workflow.ts","lineNumber":134,"sourceCode":"    const controller = new AbortController();\n    const params: OIDCCallbackParams = {\n      timeoutContext: controller.signal,\n      version: OIDC_VERSION,\n      idpInfo: idpInfo\n    };\n    if (credentials.username) {\n      params.username = credentials.username;\n    }\n    if (refreshToken) {\n      params.refreshToken = refreshToken;\n    }\n    const timeout = Timeout.expires(HUMAN_TIMEOUT_MS);\n    try {\n      return await Promise.race([this.executeAndValidateCallback(params), timeout]);\n    } catch (error) {\n      if (TimeoutError.is(error)) {\n        controller.abort();\n        throw new MongoOIDCError(`OIDC callback timed out after ${HUMAN_TIMEOUT_MS}ms.`);\n      }\n      throw error;\n    } finally {\n      timeout.clear();\n    }\n  }\n}\n","sourceCodeStart":116,"sourceCodeEnd":142,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc/human_callback_workflow.ts#L116-L142","documentation":"Thrown by the OIDC human (interactive) callback workflow (human_callback_workflow.ts:134) when the user-supplied callback function does not settle within 5 minutes (HUMAN_TIMEOUT_MS = 300000, defined in callback_workflow.ts:18). The workflow races the callback against a Timeout and, on timeout, aborts the callback via AbortController and rethrows as MongoOIDCError. This deadline exists because the human workflow performs interactive browser login.","triggerScenarios":"Registering an authMechanismProperties callback (human flow) for MONGODB-OIDC whose returned promise neither resolves nor rejects within 300000ms. Typical when the callback opens a browser/server for the user to log in and the user never completes it, or the callback awaits an event that never fires and ignores the params.timeoutContext AbortSignal.","commonSituations":"User walks away during interactive login. The callback's local HTTP server/popup hangs on a network error. The callback does not honor params.timeoutContext (the AbortSignal) and blocks forever. A token endpoint in the callback is unreachable and never times out on its own.","solutions":["Make your OIDC callback honor params.timeoutContext: abort in-flight HTTP and close popups when the signal aborts","Ensure the interactive login completes within 5 minutes, or catch the error and re-trigger connection","For non-interactive workloads, switch to a machine workflow (ENVIRONMENT=gcp/azure/k8s) or a cached token callback instead of the human flow"],"exampleFix":"// before\nconst callback = async (params) => {\n  const token = await fetchTokenIgnoreSignal(); // never aborts\n  return { accessToken: token };\n};\n\n// after\nconst callback = async (params) => {\n  const res = await fetch(tokenUrl, { signal: params.timeoutContext });\n  const json = await res.json();\n  return { accessToken: json.access_token };\n};","handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (err) {\n  if (err instanceof MongoOIDCError && /callback timed out/.test(err.message)) {\n    // re-prompt the user / re-attempt interactive login; the cache is cleared so a retry re-runs the flow\n    await retryInteractiveLogin();\n  } else throw err;\n}","preventionTips":["Always honor params.timeoutContext (AbortSignal) inside your OIDC callback and abort in-flight HTTP when it fires","Keep the interactive login UI responsive and auto-close on success","For non-interactive workloads, prefer the machine workflow over the human callback to avoid the 5-minute deadline"],"tags":["oidc","callback","timeout","authentication","interactive"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}