{"record":{"id":"7ba434ff9764e024","repo":"gofiber/fiber","slug":"failed-to-base64-decode-key-w","errorCode":null,"errorMessage":"failed to base64-decode key: %w","messagePattern":"failed to base64-decode key: %w","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/encryptcookie/utils.go","lineNumber":23,"sourceCode":"\t\"crypto/cipher\"\n\t\"crypto/rand\"\n\t\"encoding/base64\"\n\t\"errors\"\n\t\"fmt\"\n\t\"slices\"\n)\n\nvar (\n\tErrInvalidKeyLength      = errors.New(\"encryption key must be 16, 24, or 32 bytes\")\n\tErrInvalidEncryptedValue = errors.New(\"encrypted value is not valid\")\n)\n\n// decodeKey decodes the provided base64-encoded key and validates its length.\n// It returns the decoded key bytes or an error when invalid.\nfunc decodeKey(key string) ([]byte, error) {\n\tkeyDecoded, err := base64.StdEncoding.DecodeString(key)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to base64-decode key: %w\", err)\n\t}\n\n\tkeyLen := len(keyDecoded)\n\tif keyLen != 16 && keyLen != 24 && keyLen != 32 {\n\t\treturn nil, ErrInvalidKeyLength\n\t}\n\n\treturn keyDecoded, nil\n}\n\n// validateKey checks if the provided base64-encoded key is of valid length.\nfunc validateKey(key string) error {\n\t_, err := decodeKey(key)\n\treturn err\n}\n\n// EncryptCookie Encrypts a cookie value with specific encryption key\nfunc EncryptCookie(name, value, key string) (string, error) {","sourceCodeStart":5,"sourceCodeEnd":41,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/encryptcookie/utils.go#L5-L41","documentation":"Returned by decodeKey when base64.StdEncoding.DecodeString fails on the configured EncryptCookie/DecryptCookie key. The key must be valid standard base64 that decodes to 16, 24, or 32 bytes; this error fires before the length check, meaning the input is not valid base64 at all.","triggerScenarios":"EncryptCookie or DecryptCookie is called (directly or via the encryptcookie middleware) with a Key that is not valid standard-base64: contains URL-safe characters (-/_), has wrong padding, includes whitespace/newlines, or is raw hex/ASCII rather than base64.","commonSituations":"Passing a raw ASCII string instead of a base64-encoded key; using base64.URLEncoding output as a key (it contains - and _ which StdEncoding rejects); trailing newline in a key read from an env var or file; using GenerateKey's output correctly but then editing it; copy-paste truncation.","solutions":["Generate the key with encryptcookie.GenerateKey(16|24|32) — its output is valid StdEncoding base64.","If the key came from an external source, re-encode it: base64.StdEncoding.EncodeToString([]byte(rawKey)).","Strip whitespace/newlines from env-var-sourced keys before use.","If the source is URL-safe base64, translate it to standard first: base64.StdEncoding.EncodeToString(base64.URLEncoding.DecodeString(key))."],"exampleFix":"// before: raw ASCII key — not base64\napp.Use(encryptcookie.New(encryptcookie.Config{\n    Key: \"mysecretkey12345\", // fails base64 decode\n}))\n\n// after: generate a valid key (run once, store the output)\nkey := encryptcookie.GenerateKey(32) // valid StdEncoding base64\napp.Use(encryptcookie.New(encryptcookie.Config{Key: key}))","handlingStrategy":"validation","validationCode":"// Validate the key BEFORE wiring it into the middleware.\nfunc validateEncryptKey(key string) error {\n    dec, err := base64.StdEncoding.DecodeString(key)\n    if err != nil {\n        return fmt.Errorf(\"key is not valid standard base64: %w\", err)\n    }\n    if len(dec) != 16 && len(dec) != 24 && len(dec) != 32 {\n        return encryptcookie.ErrInvalidKeyLength\n    }\n    return nil\n}\n\n// at startup\nif err := validateEncryptKey(os.Getenv(\"COOKIE_KEY\")); err != nil {\n    log.Fatal(err)\n}","typeGuard":null,"tryCatchPattern":"// Prefer the middleware's own validation at boot over per-request handling.\n// encryptcookie.New calls validateKey via config; ensure Key is set from a\n// trusted generated value.\nkey := encryptcookie.GenerateKey(32)\napp.Use(encryptcookie.New(encryptcookie.Config{Key: key}))","preventionTips":["Always generate keys with encryptcookie.GenerateKey(16|24|32).","Do not hand-type or paste-edit keys; store the generated output verbatim.","Strip trailing whitespace/newlines from env-var-sourced keys.","If the source is URL-safe base64, convert to standard base64 before use."],"tags":["encryptcookie","crypto","config","base64","go","fiber"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}