apereo/cas · error · InvalidCookieException
Invalid cookie . Required fields are empty
Error message
Invalid cookie <name>. Required fields are empty
What it means
After the field-count check passes, one of the compound cookie's required parts (ticket value, client location/IP, or user-agent) is blank, so the cookie cannot be validated. InvalidCookieException marks the cookie as corrupt/emptied — the cookie exists structurally but carries no usable data in at least one mandatory field.
Solutions
- Clear the cookie and force a fresh login
- Investigate how the cookie became blank (serialization bug, tampering, storage truncation)
- Verify the component that writes the compound cookie populates all fields
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at core/cas-server-core-cookie-api/src/main/java/org/apereo/cas/web/support/mgmr/DefaultCasCookieValueManager.java:111 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of apereo/cas@e7288fc434 (2026-09-08).
Data as JSON: /api/errors/1f80d5d60e6b63b6.
Report an issue: GitHub.
Appendix: source
Thrown at core/cas-server-core-cookie-api/src/main/java/org/apereo/cas/web/support/mgmr/DefaultCasCookieValueManager.java:111
@Override
protected String obtainValueFromCompoundCookie(final String value, final HttpServletRequest request) {
val cookieParts = Splitter.on(String.valueOf(COOKIE_FIELD_SEPARATOR)).splitToList(value);
val cookieValue = cookieParts.getFirst();
if (!cookieProperties.isPinToSession()) {
LOGGER.trace("Cookie session-pinning is disabled for cookie [{}]. Returning cookie value as it was provided", cookieProperties.getName());
return cookieValue;
}
if (cookieParts.size() != COOKIE_FIELDS_LENGTH) {
throw new InvalidCookieException("Invalid cookie %s. Required fields are missing".formatted(cookieProperties.getName()));
}
val cookieClientLocationOrIp = cookieParts.get(1);
val cookieUserAgent = cookieParts.get(2);
if (Stream.of(cookieValue, cookieClientLocationOrIp, cookieUserAgent).anyMatch(StringUtils::isBlank)) {
throw new InvalidCookieException("Invalid cookie %s. Required fields are empty".formatted(cookieProperties.getName()));
}
val clientInfo = ClientInfoHolder.getClientInfo();
if (clientInfo == null) {
val message = "Unable to match required remote address %s because client ip at time of cookie creation is unknown for cookie %s"
.formatted(cookieProperties.getName(), cookieClientLocationOrIp);
LOGGER.warn(message);
throw new InvalidCookieException(message);
}
if (cookieProperties.isGeoLocateClientSession()) {
val clientLocationOrIp = getClientGeoLocation(clientInfo);
if (!cookieClientLocationOrIp.equals(clientLocationOrIp)) {
val message = "Invalid cookie %s Required remote address %s does not match %s"
.formatted(cookieProperties.getName(), cookieClientLocationOrIp, clientLocationOrIp);
LOGGER.warn(message);
throw new InvalidCookieException(message);
}View on GitHub (pinned to e7288fc434)