{"record":{"id":"4a55156abcc8d664","repo":"gofiber/fiber","slug":"cors-configuration-error-when-allowcredentials","errorCode":null,"errorMessage":"[CORS] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '*'. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting.","messagePattern":"\\[CORS\\] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '\\*'\\. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting\\.","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"middleware/cors/cors.go","lineNumber":92,"sourceCode":"\t\t\t}\n\t\t\tscheme, host, ok := strings.Cut(normalizedOrigin, \"://\")\n\t\t\tif !ok {\n\t\t\t\tpanic(\"[CORS] Invalid origin format after normalization:\" + maskValue(trimmedOrigin))\n\t\t\t}\n\t\t\tsd := subdomain{prefix: scheme + \"://\", suffix: host}\n\t\t\tallowSubOrigins = append(allowSubOrigins, sd)\n\t\t} else {\n\t\t\tisValid, normalizedOrigin := normalizeOrigin(trimmedOrigin)\n\t\t\tif !isValid {\n\t\t\t\tpanic(\"[CORS] Invalid origin format in configuration: \" + maskValue(trimmedOrigin))\n\t\t\t}\n\t\t\tallowOrigins[normalizedOrigin] = struct{}{}\n\t\t}\n\t}\n\n\t// Validate CORS credentials configuration\n\tif cfg.AllowCredentials && allowAllOrigins {\n\t\tpanic(\"[CORS] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '*'. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting.\")\n\t}\n\n\t// Warn if allowAllOrigins is set to true and AllowOriginsFunc is defined\n\tif allowAllOrigins && cfg.AllowOriginsFunc != nil {\n\t\tlog.Warn(\"[CORS] 'AllowOrigins' is set to allow all origins, 'AllowOriginsFunc' will not be used.\")\n\t}\n\n\t// Convert int to string\n\tmaxAge := strconv.Itoa(cfg.MaxAge)\n\n\t// Return new handler\n\treturn func(c fiber.Ctx) error {\n\t\t// Don't execute middleware if Next returns true\n\t\tif cfg.Next != nil && cfg.Next(c) {\n\t\t\treturn c.Next()\n\t\t}\n\n\t\t// Get origin header preserving the original case for the response","sourceCodeStart":74,"sourceCodeEnd":110,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/cors/cors.go#L74-L110","documentation":"CORS rejects an insecure combination: AllowCredentials=true together with a wildcard ('allow all') origin policy. Returning 'Access-Control-Allow-Origin: *' (or reflecting any origin) while sending credentials violates the CORS spec and lets any site make authenticated cross-origin requests — a credential-leak vulnerability. allowAllOrigins is true when AllowOrigins contains '*' (or is empty with no AllowOriginsFunc).","triggerScenarios":"cors.New(cors.Config{ AllowCredentials: true, AllowOrigins: []string{\"*\"} }) OR cors.New(cors.Config{ AllowCredentials: true /* AllowOrigins empty, AllowOriginsFunc nil */ }). Either makes allowAllOrigins true, which combined with AllowCredentials is fatal.","commonSituations":"Enabling cookies/JWT-in-cookies for a SPA and lazily setting AllowOrigins to '*'; leaving AllowOrigins empty (which means allow-all) while flipping AllowCredentials on; cargo-culting a permissive CORS config from a tutorial.","solutions":["List explicit origins in AllowOrigins (e.g. []string{\"https://app.example.com\"}) and keep AllowCredentials: true.","Alternatively, keep the wildcard policy but set AllowCredentials: false (and do not send cookies).","Use AllowOriginsFunc to dynamically allowlist known origins when credentials are required."],"exampleFix":"// before\ncors.New(cors.Config{\n    AllowCredentials: true,\n    AllowOrigins:     []string{\"*\"},\n})\n// after\ncors.New(cors.Config{\n    AllowCredentials: true,\n    AllowOrigins:     []string{\"https://app.example.com\"},\n})","handlingStrategy":"validation","validationCode":"// Reject the credentials+wildcard combination before constructing the middleware.\nallowAll := len(cfg.AllowOrigins) == 0 && cfg.AllowOriginsFunc == nil\nfor _, o := range cfg.AllowOrigins {\n    if o == \"*\" { allowAll = true }\n}\nif cfg.AllowCredentials && allowAll {\n    return errors.New(\"AllowCredentials cannot be combined with a wildcard/empty AllowOrigins\")\n}","typeGuard":null,"tryCatchPattern":"defer func() {\n    if r := recover(); r != nil {\n        log.Fatalf(\"insecure CORS config: %v\", r)\n    }\n}()\ncors.New(cfg)","preventionTips":["Never set AllowCredentials with AllowOrigins containing '*' or empty.","Use an explicit origin allowlist (or AllowOriginsFunc) when credentials are enabled.","Add a config lint that fails CI on the credentials+wildcard combination."],"tags":["middleware","cors","security","credentials","cors-misconfiguration","startup"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}