{"record":{"id":"79d1a5bc49d76da9","repo":"gofiber/fiber","slug":"fiber-keyauth-insufficient-scope-requires-scope","errorCode":null,"errorMessage":"fiber: keyauth insufficient_scope requires scope","messagePattern":"fiber: keyauth insufficient_scope requires scope","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/keyauth/config.go","lineNumber":152,"sourceCode":"\t\tcase ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope:\n\t\tdefault:\n\t\t\tpanic(\"fiber: keyauth unsupported error token\")\n\t\t}\n\t}\n\tif cfg.ErrorDescription != \"\" && cfg.Error == \"\" {\n\t\tpanic(\"fiber: keyauth error_description requires error\")\n\t}\n\tif cfg.ErrorURI != \"\" {\n\t\tif cfg.Error == \"\" {\n\t\t\tpanic(\"fiber: keyauth error_uri requires error\")\n\t\t}\n\t\tif u, err := url.Parse(cfg.ErrorURI); err != nil || !u.IsAbs() {\n\t\t\tpanic(\"fiber: keyauth error_uri must be absolute\")\n\t\t}\n\t}\n\tif cfg.Error == ErrorInsufficientScope {\n\t\tif cfg.Scope == \"\" {\n\t\t\tpanic(\"fiber: keyauth insufficient_scope requires scope\")\n\t\t}\n\t\tfor scope := range strings.SplitSeq(cfg.Scope, \" \") {\n\t\t\tif scope == \"\" || !isScopeToken(scope) {\n\t\t\t\tpanic(\"fiber: keyauth scope contains invalid token\")\n\t\t\t}\n\t\t}\n\t} else if cfg.Scope != \"\" {\n\t\tpanic(\"fiber: keyauth scope requires insufficient_scope error\")\n\t}\n\n\treturn cfg\n}\n\nfunc isScopeToken(s string) bool {\n\tfor i := 0; i < len(s); i++ {\n\t\tc := s[i]\n\t\tif c < 0x21 || c > 0x7e || c == '\"' || c == '\\\\' {\n\t\t\treturn false","sourceCodeStart":134,"sourceCodeEnd":170,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/keyauth/config.go#L134-L170","documentation":"When Config.Error equals ErrorInsufficientScope, keyauth requires Config.Scope to be non-empty. RFC 6750 says an insufficient_scope challenge should carry the scope required to access the resource, so the client knows what to request. An empty Scope with that error code is invalid.","triggerScenarios":"keyauth.Config{Error: keyauth.ErrorInsufficientScope} with Scope unset, or Scope populated only in a branch that did not execute.","commonSituations":"Setting Error to insufficient_scope because of a checklist without supplying the required scope string; per-route config where the scope is meant to be injected but the injection was missed.","solutions":["Set Config.Scope to the space-delimited list of required scopes, e.g. \"read write\".","If you did not mean insufficient_scope, pick the correct Error code (invalid_token / invalid_request) or leave Error empty.","Validate at config load: Error == ErrorInsufficientScope implies Scope != \"\"."],"exampleFix":"// before\napp.Use(keyauth.New(keyauth.Config{\n    Validator: v,\n    Error:     keyauth.ErrorInsufficientScope,\n}))\n\n// after\napp.Use(keyauth.New(keyauth.Config{\n    Validator: v,\n    Error:     keyauth.ErrorInsufficientScope,\n    Scope:     \"admin\",\n}))","handlingStrategy":"validation","validationCode":"if cfg.Error == keyauth.ErrorInsufficientScope && cfg.Scope == \"\" {\n    log.Fatal(\"keyauth: insufficient_scope requires a non-empty Scope\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Whenever Error is insufficient_scope, immediately set Scope in the same edit.","Encode the constraint in your config builder: ErrorInsufficientScope ⇒ Scope set.","Add a test that builds the config for each Error code and asserts the required companions."],"tags":["keyauth","oauth","rfc-6750","scope","config","auth","startup-panic"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}