redis/node-redis · error · Error

SESSION_SECRET environment variable must be set

Error message

SESSION_SECRET environment variable must be set

What it means

The `interactive-browser` sample uses the same Express + express-session bootstrap and applies the identical `SESSION_SECRET` startup guard in its own entry file. It refuses to boot without the secret, independent of the auth-code-pkce sample.

Solutions

  1. Add `SESSION_SECRET=<long-random-string>` to the sample's `.env`.
  2. Export `SESSION_SECRET` in the runtime environment.
  3. Generate a strong random secret (e.g. `openssl rand -hex 32`).

Example fix

# .env (before: missing)
# after
SESSION_SECRET=$(openssl rand -hex 32)
Defensive patterns

Strategy: validation

Validate before calling

function requireEnv(name: string): string {
  const v = process.env[name];
  if (!v) throw new Error(`${name} environment variable must be set`);
  return v;
}
const SESSION_SECRET = requireEnv('SESSION_SECRET');

Type guard

function hasEnv(name: string): boolean { return Boolean(process.env[name]); }

Prevention

When it happens

Trigger: Running `packages/entraid/samples/interactive-browser` without `SESSION_SECRET` in the environment / `.env`. Throws at module load, before `InteractiveBrowserCredential` is constructed.

Common situations: Missing `.env` for this sample specifically; container/CI without the var; copied the sample folder without its env template.

Related errors


AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11). Data as JSON: /api/errors/2db32a57c0accd16. Report an issue: GitHub.

Appendix: source

Thrown at packages/entraid/samples/interactive-browser/index.ts:10

import express, { Request, Response } from 'express';
import session from 'express-session';
import dotenv from 'dotenv';
import { DEFAULT_TOKEN_MANAGER_CONFIG, EntraIdCredentialsProviderFactory } from '../../lib/entra-id-credentials-provider-factory';
import { InteractiveBrowserCredential } from '@azure/identity';

dotenv.config();

if (!process.env.SESSION_SECRET) {
  throw new Error('SESSION_SECRET environment variable must be set');
}

const app = express();

const sessionConfig = {
  secret: process.env.SESSION_SECRET,
  resave: false,
  saveUninitialized: false,
  cookie: {
    secure: process.env.NODE_ENV === 'production', // Only use secure in production
    httpOnly: true,
    sameSite: 'lax',
    maxAge: 3600000 // 1 hour
  }
} as const;

app.use(session(sessionConfig));

View on GitHub (pinned to 90fd0652bc)