redis/node-redis · error · Error
SESSION_SECRET environment variable must be set
Error message
SESSION_SECRET environment variable must be set
What it means
The `interactive-browser` sample uses the same Express + express-session bootstrap and applies the identical `SESSION_SECRET` startup guard in its own entry file. It refuses to boot without the secret, independent of the auth-code-pkce sample.
Solutions
- Add `SESSION_SECRET=<long-random-string>` to the sample's `.env`.
- Export `SESSION_SECRET` in the runtime environment.
- Generate a strong random secret (e.g. `openssl rand -hex 32`).
Example fix
# .env (before: missing) # after SESSION_SECRET=$(openssl rand -hex 32)
Defensive patterns
Strategy: validation
Validate before calling
function requireEnv(name: string): string {
const v = process.env[name];
if (!v) throw new Error(`${name} environment variable must be set`);
return v;
}
const SESSION_SECRET = requireEnv('SESSION_SECRET'); Type guard
function hasEnv(name: string): boolean { return Boolean(process.env[name]); } Prevention
- Give each sample its own `.env` derived from `.env.example`.
- Generate strong random secrets with `openssl rand -hex 32`.
When it happens
Trigger: Running `packages/entraid/samples/interactive-browser` without `SESSION_SECRET` in the environment / `.env`. Throws at module load, before `InteractiveBrowserCredential` is constructed.
Common situations: Missing `.env` for this sample specifically; container/CI without the var; copied the sample folder without its env template.
Related errors
- SESSION_SECRET environment variable must be set
- MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…
- MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…
- Database not found in
- Invalid authority configuration
AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11).
Data as JSON: /api/errors/2db32a57c0accd16.
Report an issue: GitHub.
Appendix: source
Thrown at packages/entraid/samples/interactive-browser/index.ts:10
import express, { Request, Response } from 'express';
import session from 'express-session';
import dotenv from 'dotenv';
import { DEFAULT_TOKEN_MANAGER_CONFIG, EntraIdCredentialsProviderFactory } from '../../lib/entra-id-credentials-provider-factory';
import { InteractiveBrowserCredential } from '@azure/identity';
dotenv.config();
if (!process.env.SESSION_SECRET) {
throw new Error('SESSION_SECRET environment variable must be set');
}
const app = express();
const sessionConfig = {
secret: process.env.SESSION_SECRET,
resave: false,
saveUninitialized: false,
cookie: {
secure: process.env.NODE_ENV === 'production', // Only use secure in production
httpOnly: true,
sameSite: 'lax',
maxAge: 3600000 // 1 hour
}
} as const;
app.use(session(sessionConfig));
View on GitHub (pinned to 90fd0652bc)