{"record":{"id":"24ac6a0db0c92139","repo":"gofiber/fiber","slug":"fiber-encrypt-cookie-middleware-requires-key","errorCode":null,"errorMessage":"fiber: encrypt cookie middleware requires key","messagePattern":"fiber: encrypt cookie middleware requires key","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"middleware/encryptcookie/config.go","lineNumber":74,"sourceCode":"\t\tif cfg.Next == nil {\n\t\t\tcfg.Next = ConfigDefault.Next\n\t\t}\n\n\t\tif cfg.Except == nil {\n\t\t\tcfg.Except = ConfigDefault.Except\n\t\t}\n\n\t\tif cfg.Encryptor == nil {\n\t\t\tcfg.Encryptor = ConfigDefault.Encryptor\n\t\t}\n\n\t\tif cfg.Decryptor == nil {\n\t\t\tcfg.Decryptor = ConfigDefault.Decryptor\n\t\t}\n\t}\n\n\tif cfg.Key == \"\" {\n\t\tpanic(\"fiber: encrypt cookie middleware requires key\")\n\t}\n\n\tif err := validateKey(cfg.Key); err != nil {\n\t\tpanic(err)\n\t}\n\n\treturn cfg\n}\n","sourceCodeStart":56,"sourceCodeEnd":83,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/encryptcookie/config.go#L56-L83","documentation":"The encryptcookie middleware requires a symmetric AES key to encrypt/decrypt cookie values; an empty Config.Key provides no security and is rejected at startup with panic. The empty-key check runs after defaulting Encryptor/Decryptor but before validateKey, so an empty key fails fast with a clear message rather than a downstream AES error.","triggerScenarios":"encryptcookie.New(encryptcookie.Config{ /* Key omitted */ }) or encryptcookie.New(encryptcookie.Config{ Key: \"\" }) — typically because the key was meant to be loaded from an environment variable or secret store that resolved to empty (unset env var, wrong key name, missing file).","commonSituations":"Forgetting to set the COOKIE_KEY env var; typo in the env var name in os.Getenv; secret not mounted in a container/Kubernetes deployment; running a new environment (CI, staging) without provisioning the key; reading the key from a config file that was git-ignored and is absent.","solutions":["Provision a key with encryptcookie.GenerateKey(32) and pass it: Config{ Key: key }.","Load the key from a secret store/env var and fail loudly at boot if it is empty: key := os.Getenv(\"COOKIE_KEY\"); if key == \"\" { log.Fatal(...) }.","Ensure the same key is distributed to every instance that must read the encrypted cookies (key rotation requires dual-key handling)."],"exampleFix":"// before\napp.Use(encryptcookie.New(encryptcookie.Config{}))\n// after\nkey := os.Getenv(\"COOKIE_KEY\")\nif key == \"\" { log.Fatal(\"COOKIE_KEY not set\") }\napp.Use(encryptcookie.New(encryptcookie.Config{ Key: key }))","handlingStrategy":"validation","validationCode":"key := os.Getenv(\"COOKIE_KEY\")\nif key == \"\" {\n    log.Fatal(\"COOKIE_KEY is not set; generate one with encryptcookie.GenerateKey(32)\")\n}\n// optional: validate decode length up front\nif err := encryptcookie.GenerateKey /* unused */; false {\n}\napp.Use(encryptcookie.New(encryptcookie.Config{ Key: key }))","typeGuard":null,"tryCatchPattern":"defer func() {\n    if r := recover(); r != nil {\n        log.Fatalf(\"encryptcookie key missing/invalid: %v\", r)\n    }\n}()\napp.Use(encryptcookie.New(cfg))","preventionTips":["Provision the key in a secret manager; never commit it.","Fail fast at boot if the key env var is empty.","Distribute the same key to all instances sharing the cookies; plan key rotation explicitly."],"tags":["middleware","encryptcookie","security","config","key-management","startup"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}