{"record":{"id":"3d17d41087a22d6f","repo":"gofiber/fiber","slug":"csrf-failed-to-delete-token-from-storage-w","errorCode":null,"errorMessage":"csrf: failed to delete token from storage: %w","messagePattern":"csrf: failed to delete token from storage: %w","errorType":"http","errorClass":null,"httpStatus":500,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":297,"sourceCode":"// createOrExtendTokenInStorage creates or extends the token in the storage\nfunc createOrExtendTokenInStorage(c fiber.Ctx, token string, cfg *Config, sessionManager *sessionManager, storageManager *storageManager) error {\n\tif cfg.Session != nil {\n\t\tsessionManager.setRaw(c, token, dummyValue, cfg.IdleTimeout)\n\t\treturn nil\n\t}\n\tif err := storageManager.setRaw(c, token, dummyValue, cfg.IdleTimeout); err != nil {\n\t\treturn fmt.Errorf(\"csrf: failed to store token in storage: %w\", err)\n\t}\n\treturn nil\n}\n\nfunc deleteTokenFromStorage(c fiber.Ctx, token string, cfg *Config, sessionManager *sessionManager, storageManager *storageManager) error {\n\tif cfg.Session != nil {\n\t\tsessionManager.delRaw(c)\n\t\treturn nil\n\t}\n\tif err := storageManager.delRaw(c, token); err != nil {\n\t\treturn fmt.Errorf(\"csrf: failed to delete token from storage: %w\", err)\n\t}\n\treturn nil\n}\n\n// Update CSRF cookie\n// if expireCookie is true, the cookie will expire immediately\nfunc updateCSRFCookie(c fiber.Ctx, cfg *Config, token string) {\n\tsetCSRFCookie(c, cfg, token, cfg.IdleTimeout)\n}\n\nfunc expireCSRFCookie(c fiber.Ctx, cfg *Config) {\n\tsetCSRFCookie(c, cfg, \"\", -time.Hour)\n}\n\nfunc setCSRFCookie(c fiber.Ctx, cfg *Config, token string, expiry time.Duration) {\n\tcookie := &fiber.Cookie{\n\t\tName:        cfg.CookieName,\n\t\tValue:       token,","sourceCodeStart":279,"sourceCodeEnd":315,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L279-L315","documentation":"Returned by deleteTokenFromStorage when storageManager.delRaw fails during CSRF token invalidation (logout, double-submit cleanup, token rotation). The token remains in storage and could still validate a request until it expires via TTL.","triggerScenarios":"Token invalidation flow (logout, failed-validation purge, single-use token consumption) where the Storage DeleteWithContext errors. Only on the external-Storage branch (cfg.Session nil).","commonSituations":"Storage outage during logout; ACL missing DEL permission; connection error; context cancellation; backend failover mid-delete. The token will linger until its TTL elapses, slightly widening its validity window.","solutions":["Inspect the wrapped error for permission/connectivity/cancellation.","Ensure Storage credentials include DEL permission.","Keep IdleTimeout (TTL) short enough that a failed delete self-heals quickly.","Log the failure; do not block the user-facing logout flow on it — the TTL is the safety net."],"exampleFix":"// before: failing logout because the token delete errored\nif err := storageManager.delRaw(c, token); err != nil {\n    return fmt.Errorf(\"csrf: failed to delete token from storage: %w\", err)\n}\n\n// after: best-effort delete, TTL is the backstop\nif err := storageManager.delRaw(c, token); err != nil {\n    log.Warn(\"csrf token delete failed; will expire via TTL:\", err)\n}","handlingStrategy":"fallback","validationCode":"func validateCsrfDelete(ctx context.Context, s fiber.Storage) error {\n    _ = s.SetWithContext(ctx, \"__csrf_del__\", []byte(\"x\"), time.Second)\n    return s.DeleteWithContext(ctx, \"__csrf_del__\")\n}","typeGuard":null,"tryCatchPattern":"// Logout/invalidation should not fail because the delete errored.\nif err := storageManager.delRaw(c, token); err != nil {\n    log.Warn(\"csrf token delete failed; TTL will expire it:\", err)\n}\nreturn nil","preventionTips":["Grant DEL permission on the Storage credentials.","Keep IdleTimeout short so failed deletes self-heal.","Do not block logout on a best-effort token delete."],"tags":["csrf","storage","auth","delete","security","go","fiber"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}