koala73/worldmonitor · critical · Error

Redis not configured

Error message

Redis not configured

What it means

Thrown by `redisConfig()` in api/oauth/_refresh-recovery.ts:187 when either `UPSTASH_REDIS_REST_URL` or `UPSTASH_REDIS_REST_TOKEN` is missing from the environment. The OAuth refresh-recovery flow on Vercel Edge needs these to reach Upstash Redis over HTTP for atomic compare-and-set operations protecting refresh-token replay. Without them, no Redis call can even be attempted.

Solutions

  1. Set both `UPSTASH_REDIS_REST_URL` and `UPSTASH_REDIS_REST_TOKEN` in the deployment environment (Vercel project env or local .env/.env.local)
  2. Verify they are present in the environment the Edge function actually runs in (production vs preview vs dev), not just the shell
  3. After fixing, confirm the refresh flow succeeds; callers already degrade gracefully because finalize/protect paths catch these errors

Example fix

# before (env missing)
# after
UPSTASH_REDIS_REST_URL=https://your-db.upstash.io
UPSTASH_REDIS_REST_TOKEN=AXX...
Defensive patterns

Strategy: fallback

Validate before calling

const hasRedis = Boolean(process.env.UPSTASH_REDIS_REST_URL && process.env.UPSTASH_REDIS_REST_TOKEN);
if (!hasRedis) {
  // skip recovery path or fail fast with a config error before calling refresh recovery
}

Try / catch

try {
  await beginRefreshAttempt(token, id);
} catch (e) {
  if (e instanceof Error && e.message === 'Redis not configured') {
    // config problem: surface a deployment error, do not retry
  } else throw e;
}

Prevention

When it happens

Trigger: Any invocation of `rawRedisBeginRefreshAttempt`, `rawRedisRestoreRefreshAttempt`, or `rawRedisFinalizeRefreshAttempt` (i.e. an OAuth token refresh with recovery handling) when one or both env vars are unset in the Edge runtime.

Common situations: Deploying the Edge functions without linking the Upstash env vars; local development lacking `.env.local`; rotating/upstairs Redis credentials and only setting one var; targeting a preview environment that never received the secrets.

Understand the failure class

Background: "environment variable is not set" and "Missing keys in environment" errors: what missing required env var messages mean and how to fix them — this error's family across 28 libraries.

Related errors


AI-assisted analysis of koala73/worldmonitor@a96956387a (2026-08-27). Data as JSON: /api/errors/a7933dd3bb2c982a. Report an issue: GitHub.

Appendix: source

Thrown at api/oauth/_refresh-recovery.ts:187

  return false;
}

export async function finalizeRefreshAttempt(
  deps: Pick<RefreshRecoveryDeps, 'redisFinalizeRefreshAttempt'>,
  refreshToken: string,
  attemptValue: string,
): Promise<boolean> {
  try {
    return await deps.redisFinalizeRefreshAttempt(refreshToken, attemptValue);
  } catch {
    return false;
  }
}

function redisConfig(): { url: string; token: string } {
  const url = process.env.UPSTASH_REDIS_REST_URL;
  const token = process.env.UPSTASH_REDIS_REST_TOKEN;
  if (!url || !token) throw new Error('Redis not configured');
  return { url, token };
}

async function rawRedisEval(
  script: string,
  keys: string[],
  args: Array<string | number>,
): Promise<unknown> {
  const { url, token } = redisConfig();
  const resp = await fetch(`${url}/`, {
    method: 'POST',
    headers: {
      Authorization: `Bearer ${token}`,
      'Content-Type': 'application/json',
      'User-Agent': 'worldmonitor-edge/1.0',
    },
    body: JSON.stringify(['EVAL', script, String(keys.length), ...keys, ...args]),
    signal: AbortSignal.timeout(3_000),

View on GitHub (pinned to a96956387a)