redis/node-redis · error · Error

Invalid authority configuration

Error message

Invalid authority configuration

What it means

`EntraIdCredentialsProviderFactory.getAuthority()` switches on `config.type` and only knows `'multi-tenant'`, `'custom'`, and `'default'` (the `AuthorityConfig` discriminated union). Any other value hits the `default` branch and throws 'Invalid authority configuration'. TypeScript narrows the union so this is primarily a runtime/JSDoc-default concern when config arrives untyped.

Solutions

  1. Use exactly one of: `{ type: 'multi-tenant', tenantId }`, `{ type: 'custom', authorityUrl }`, or `{ type: 'default' }`.
  2. Validate/normalize the `type` string before constructing the config (case-sensitive).
  3. Type the config source as `AuthorityConfig` so the compiler rejects bad values.

Example fix

// before
getAuthority({ type: 'multitenant', tenantId: 'xxx' }); // typo
// after
getAuthority({ type: 'multi-tenant', tenantId: 'xxx' });
Defensive patterns

Strategy: type-guard

Validate before calling

function normalizeAuthority(c: unknown) {
  if (c && typeof c === 'object' && 'type' in c) {
    const t = (c as { type: string }).type;
    if (t === 'multi-tenant' || t === 'custom' || t === 'default') return c;
  }
  throw new Error(`Unknown authority type; expected multi-tenant|custom|default`);
}

Type guard

function isAuthorityConfig(c: unknown): c is { type: 'multi-tenant'; tenantId: string } | { type: 'custom'; authorityUrl: string } | { type: 'default' } {
  if (!c || typeof c !== 'object') return false;
  const t = (c as { type?: unknown }).type;
  return t === 'multi-tenant' || t === 'custom' || t === 'default';
}

Try / catch

try { EntraIdCredentialsProviderFactory.getAuthority(cfg); }
catch (e) {
  if (String(e).includes('Invalid authority configuration')) {
    cfg = { type: 'default' as const };
    EntraIdCredentialsProviderFactory.getAuthority(cfg);
  } else throw e;
}

Prevention

When it happens

Trigger: Passing an `AuthorityConfig` whose `type` is not one of the three valid literals, e.g. from parsed JSON/env where the field is missing, misspelled ('multitenant'), or lowercased differently.

Common situations: Loading authority config from environment/JSON without validation; typo in the discriminator; version skew where a caller sends an old/new type string.

Related errors


AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11). Data as JSON: /api/errors/9283ac9ba7b763da. Report an issue: GitHub.

Appendix: source

Thrown at packages/entraid/lib/entra-id-credentials-provider-factory.ts:258

        return new EntraidCredentialsProvider(tm, idp, {
          onReAuthenticationError: params.onReAuthenticationError,
          credentialsMapper: params.credentialsMapper ?? DEFAULT_CREDENTIALS_MAPPER,
          onRetryableError: params.onRetryableError
        });
      }
    };
  }

  static getAuthority(config: AuthorityConfig): string {
    switch (config.type) {
      case 'multi-tenant':
        return `https://login.microsoftonline.com/${config.tenantId}`;
      case 'custom':
        return config.authorityUrl;
      case 'default':
        return 'https://login.microsoftonline.com/common';
      default:
        throw new Error('Invalid authority configuration');
    }
  }

}

export const REDIS_SCOPE_DEFAULT = 'https://redis.azure.com/.default';
export const REDIS_SCOPE = 'https://redis.azure.com'

export type AuthorityConfig =
  | { type: 'multi-tenant'; tenantId: string }
  | { type: 'custom'; authorityUrl: string }
  | { type: 'default' };

export type PKCEParams = {
  code: string;
  verifier: string;
  clientInfo?: string;
}

View on GitHub (pinned to 90fd0652bc)