{"record":{"id":"71dc44d88c381fe0","repo":"gofiber/fiber","slug":"csrf-failed-to-get-value-from-storage-w","errorCode":null,"errorMessage":"csrf: failed to get value from storage: %w","messagePattern":"csrf: failed to get value from storage: %w","errorType":"http","errorClass":null,"httpStatus":500,"severity":"error","filePath":"middleware/csrf/storage_manager.go","lineNumber":40,"sourceCode":"\tstorageManager := &storageManager{\n\t\tshouldRedactKeys: shouldRedactKeys,\n\t}\n\tif storage != nil {\n\t\t// Use provided storage if provided\n\t\tstorageManager.storage = storage\n\t} else {\n\t\t// Fallback to memory storage\n\t\tstorageManager.memory = memory.New()\n\t}\n\treturn storageManager\n}\n\n// get raw data from storage or memory\nfunc (m *storageManager) getRaw(ctx context.Context, key string) ([]byte, error) {\n\tif m.storage != nil {\n\t\traw, err := m.storage.GetWithContext(ctx, key)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"csrf: failed to get value from storage: %w\", err)\n\t\t}\n\t\treturn raw, nil\n\t}\n\n\tif value := m.memory.Get(key); value != nil {\n\t\traw, ok := value.([]byte)\n\t\tif !ok {\n\t\t\treturn nil, fmt.Errorf(\"csrf: unexpected value type %T in storage\", value)\n\t\t}\n\t\treturn raw, nil\n\t}\n\n\treturn nil, nil\n}\n\n// set data to storage or memory\nfunc (m *storageManager) setRaw(ctx context.Context, key string, raw []byte, exp time.Duration) error {\n\tif m.storage != nil {","sourceCodeStart":22,"sourceCodeEnd":58,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/storage_manager.go#L22-L58","documentation":"Returned by storageManager.getRaw (the lower-level call beneath getRawFromStorage) when the external Storage's GetWithContext errors reading a CSRF token. This is the storage-driver-level failure that surfaces upward as error 151.","triggerScenarios":"CSRF token verification with cfg.Storage set; Storage.GetWithContext returns a non-nil error for the token key. Driver/connection/protocol-level failure in the configured Storage implementation.","commonSituations":"Redis/storage unreachable, auth failure, pool exhaustion, TLS errors, context cancellation, custom Storage impl returning errors for missing keys instead of (nil,nil).","solutions":["Examine the wrapped error to pinpoint the driver-level cause.","Verify Storage connectivity/auth and connection pool configuration.","If using a custom Storage implementation, ensure GetWithContext distinguishes 'not found' (return nil,nil) from genuine errors.","Tune timeouts and pool size; add health checks/circuit breaking."],"exampleFix":"// Custom Storage impl: never return an error for a missing key.\n// before\nfunc (s *MyStore) GetWithContext(ctx context.Context, key string) ([]byte, error) {\n    v, ok := s.m.Load(key)\n    if !ok {\n        return nil, errors.New(\"not found\") // WRONG — surfaces as 154\n    }\n    return v.([]byte), nil\n}\n\n// after\nfunc (s *MyStore) GetWithContext(ctx context.Context, key string) ([]byte, error) {\n    v, ok := s.m.Load(key)\n    if !ok {\n        return nil, nil // correct: nil value signals absence\n    }\n    return v.([]byte), nil\n}","handlingStrategy":"retry","validationCode":"// Custom Storage impls MUST return (nil, nil) for missing keys.\n// Validate this contract before deploying.\nfunc validateStorageContract(ctx context.Context, s fiber.Storage) error {\n    got, err := s.GetWithContext(ctx, \"__nonexistent__\")\n    if err != nil {\n        return fmt.Errorf(\"GetWithContext must not error on absent key: %w\", err)\n    }\n    if got != nil {\n        return fmt.Errorf(\"GetWithContext must return nil value for absent key\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"raw, err := m.storage.GetWithContext(ctx, key)\nif err != nil {\n    if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {\n        return nil, err\n    }\n    log.Error(\"csrf storage get failed; treating as absent (reject token):\", err)\n    return nil, nil // caller will reject the token\n}","preventionTips":["Implement custom Storage with (nil,nil) on miss, error only on real failures.","Monitor Storage health; CSRF gates state-changing requests.","Tune connection pool and timeouts to your backend."],"tags":["csrf","storage","network","auth","go","fiber"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}