{"record":{"id":"1f80d5d60e6b63b6","repo":"apereo/cas","slug":"invalid-cookie-name-required-fields-are-empty","errorCode":null,"errorMessage":"Invalid cookie <name>. Required fields are empty","messagePattern":"Invalid cookie <name>\\. Required fields are empty","errorType":"exception","errorClass":"InvalidCookieException","httpStatus":null,"severity":"error","filePath":"core/cas-server-core-cookie-api/src/main/java/org/apereo/cas/web/support/mgmr/DefaultCasCookieValueManager.java","lineNumber":111,"sourceCode":"\n    @Override\n    protected String obtainValueFromCompoundCookie(final String value, final HttpServletRequest request) {\n        val cookieParts = Splitter.on(String.valueOf(COOKIE_FIELD_SEPARATOR)).splitToList(value);\n\n        val cookieValue = cookieParts.getFirst();\n        if (!cookieProperties.isPinToSession()) {\n            LOGGER.trace(\"Cookie session-pinning is disabled for cookie [{}]. Returning cookie value as it was provided\", cookieProperties.getName());\n            return cookieValue;\n        }\n\n        if (cookieParts.size() != COOKIE_FIELDS_LENGTH) {\n            throw new InvalidCookieException(\"Invalid cookie %s. Required fields are missing\".formatted(cookieProperties.getName()));\n        }\n        val cookieClientLocationOrIp = cookieParts.get(1);\n        val cookieUserAgent = cookieParts.get(2);\n\n        if (Stream.of(cookieValue, cookieClientLocationOrIp, cookieUserAgent).anyMatch(StringUtils::isBlank)) {\n            throw new InvalidCookieException(\"Invalid cookie %s. Required fields are empty\".formatted(cookieProperties.getName()));\n        }\n\n        val clientInfo = ClientInfoHolder.getClientInfo();\n        if (clientInfo == null) {\n            val message = \"Unable to match required remote address %s because client ip at time of cookie creation is unknown for cookie %s\"\n                .formatted(cookieProperties.getName(), cookieClientLocationOrIp);\n            LOGGER.warn(message);\n            throw new InvalidCookieException(message);\n        }\n\n        if (cookieProperties.isGeoLocateClientSession()) {\n            val clientLocationOrIp = getClientGeoLocation(clientInfo);\n            if (!cookieClientLocationOrIp.equals(clientLocationOrIp)) {\n                val message = \"Invalid cookie %s Required remote address %s does not match %s\"\n                    .formatted(cookieProperties.getName(), cookieClientLocationOrIp, clientLocationOrIp);\n                LOGGER.warn(message);\n                throw new InvalidCookieException(message);\n            }","sourceCodeStart":93,"sourceCodeEnd":129,"githubUrl":"https://github.com/apereo/cas/blob/e7288fc434b4f4505b8452e1a57e8fb3111bb863/core/cas-server-core-cookie-api/src/main/java/org/apereo/cas/web/support/mgmr/DefaultCasCookieValueManager.java#L93-L129","documentation":"After the field-count check passes, one of the compound cookie's required parts (ticket value, client location/IP, or user-agent) is blank, so the cookie cannot be validated. InvalidCookieException marks the cookie as corrupt/emptied — the cookie exists structurally but carries no usable data in at least one mandatory field.","triggerScenarios":"Thrown at core/cas-server-core-cookie-api/src/main/java/org/apereo/cas/web/support/mgmr/DefaultCasCookieValueManager.java:111 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Clear the cookie and force a fresh login","Investigate how the cookie became blank (serialization bug, tampering, storage truncation)","Verify the component that writes the compound cookie populates all fields"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"e7288fc434b4f4505b8452e1a57e8fb3111bb863","analyzedAt":"2026-09-08T15:39:16.015Z","contentChangedAt":"2026-09-08T15:39:16.015Z","schemaVersion":2},"datasetVersion":"2026-09-15T23:17:13.987Z"}