{"record":{"id":"6bb342649d1f142b","repo":"gofiber/fiber","slug":"failed-to-create-aes-cipher-w","errorCode":null,"errorMessage":"failed to create AES cipher: %w","messagePattern":"failed to create AES cipher: %w","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/encryptcookie/utils.go","lineNumber":49,"sourceCode":"\treturn keyDecoded, nil\n}\n\n// validateKey checks if the provided base64-encoded key is of valid length.\nfunc validateKey(key string) error {\n\t_, err := decodeKey(key)\n\treturn err\n}\n\n// EncryptCookie Encrypts a cookie value with specific encryption key\nfunc EncryptCookie(name, value, key string) (string, error) {\n\tkeyDecoded, err := decodeKey(key)\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\n\tblock, err := aes.NewCipher(keyDecoded)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to create AES cipher: %w\", err)\n\t}\n\n\tgcm, err := cipher.NewGCMWithRandomNonce(block)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to create GCM mode: %w\", err)\n\t}\n\n\tciphertext := gcm.Seal(nil, nil, []byte(value), []byte(name))\n\treturn base64.StdEncoding.EncodeToString(ciphertext), nil\n}\n\n// DecryptCookie Decrypts a cookie value with specific encryption key\nfunc DecryptCookie(name, value, key string) (string, error) {\n\tkeyDecoded, err := decodeKey(key)\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n","sourceCodeStart":31,"sourceCodeEnd":67,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/encryptcookie/utils.go#L31-L67","documentation":"Returned by EncryptCookie (and DecryptCookie) when aes.NewCipher fails on the decoded key. Because decodeKey already validated the length to be 16/24/32 bytes, aes.NewCipher should not fail in practice — it can only fail on a non-positive key length, which the prior guard excludes. Encountering it indicates an unexpected crypto/library state or a key whose length validation was bypassed.","triggerScenarios":"Only reachable if aes.NewCipher returns an error for a key that decodeKey accepted — i.e. effectively unreachable under the documented contract. Hypothetically: a malformed build, a forked/patched decodeKey that skipped length validation, or a corrupted crypto/aes package.","commonSituations":"Not encountered in normal operation. If seen, suspect a code path that calls aes.NewCipher with an unvalidated key (bypassing decodeKey), or an exotic platform/toolchain issue. Treat as a defense-in-depth guard rather than an operational error.","solutions":["Confirm the key reaches EncryptCookie via the public API and decodeKey (which enforces length) — do not call aes.NewCipher directly with user input.","Regenerate the key with GenerateKey to rule out malformed key material.","Rebuild with a stock Go toolchain to rule out a corrupted crypto/aes.","Treat as a bug if reproduced with a valid 16/24/32-byte key through the public API."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate the key material end-to-end at startup by performing a roundtrip.\nfunc validateKeyRoundtrip(key string) error {\n    enc, err := encryptcookie.EncryptCookie(\"probe\", \"v\", key)\n    if err != nil {\n        return fmt.Errorf(\"encrypt roundtrip failed: %w\", err)\n    }\n    if _, err := encryptcookie.DecryptCookie(\"probe\", enc, key); err != nil {\n        return fmt.Errorf(\"decrypt roundtrip failed: %w\", err)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// Practically unreachable; guard at the boundary by validating the key once\n// at boot rather than per request.\nif err := validateKeyRoundtrip(cfg.Key); err != nil {\n    log.Fatal(\"encryptcookie key invalid:\", err)\n}","preventionTips":["Route keys through decodeKey (via the public API) so length is validated before aes.NewCipher.","Generate keys with GenerateKey; do not construct key bytes manually.","Run a startup roundtrip probe to catch any toolchain/crypto anomaly early."],"tags":["encryptcookie","crypto","aes","invariant","go","fiber"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}