{"record":{"id":"945cf4d40e754078","repo":"apache/seatunnel","slug":"invalid-secret-key-aes-256-requires-exactly-32-by","errorCode":null,"errorMessage":"Invalid secret_key: AES-256 requires exactly 32 bytes, but got %d bytes after Base64 decoding","messagePattern":"Invalid secret_key: AES-256 requires exactly 32 bytes, but got (.+?) bytes after Base64 decoding","errorType":"validation","errorClass":"OptionValidationException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/source/EdgeSocketSourceFactory.java","lineNumber":161,"sourceCode":"                return true;\n            }\n            EdgeSocketPacketMode packetMode;\n            try {\n                packetMode = config.get(EdgeSocketSourceOptions.PACKET_MODE);\n            } catch (IllegalArgumentException exception) {\n                return true;\n            }\n            if (packetMode != EdgeSocketPacketMode.PACKET) {\n                return true;\n            }\n            byte[] secretKeyBytes;\n            try {\n                secretKeyBytes = Base64.getDecoder().decode(secretKey);\n            } catch (IllegalArgumentException exception) {\n                throw new OptionValidationException(\"Invalid secret_key: not Base64 encoded\");\n            }\n            if (secretKeyBytes.length != 32) {\n                throw new OptionValidationException(\n                        \"Invalid secret_key: AES-256 requires exactly 32 bytes, \"\n                                + \"but got %d bytes after Base64 decoding\",\n                        secretKeyBytes.length);\n            }\n            return true;\n        }\n    }\n}\n","sourceCodeStart":143,"sourceCodeEnd":170,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/source/EdgeSocketSourceFactory.java#L143-L170","documentation":"After successful Base64 decoding, the secret_key must be exactly 32 bytes for AES-256. Validation rejects any other decoded length (16-byte AES-128 keys, empty keys, truncated Base64) with an OptionValidationException stating the required and actual byte counts.","triggerScenarios":"evaluate() decodes the secret_key and its byte[] length differs from 32 — e.g. a 16-byte AES-128 key, a 24-byte AES-192 key, a key generated with `openssl rand -base64 16`, or a truncated Base64 string.","commonSituations":"Reusing a key generated for AES-128 from another component; generating a key with a default size other than 32 bytes; copy/paste dropping trailing characters; sender/receiver key lengths drifting apart after a config update.","solutions":["Regenerate with exactly 32 bytes: `openssl rand -base64 32` and verify decoded length is 32.","If you have a 16-byte key and must keep it, note the connector requires AES-256 — pad/derive via a KDF only if both sides agree; otherwise regenerate as 32 bytes.","Base64-decode locally (`base64 -d | wc -c`) to confirm the length before deploying.","Synchronize the corrected key on all sender and receiver nodes."],"exampleFix":"// before\nsecret_key = \"MTIzNDU2Nzg5MGFiY2RlZg==\" // decodes to 16 bytes\n// after\nsecret_key = \"ASIscmWlnSPjJDvFXT4fzn9WXCFxHqcueqcbfXhz1Ro=\" // 32 bytes","handlingStrategy":"validation","validationCode":"byte[] keyBytes = Base64.getDecoder().decode(secretKey);\nif (keyBytes.length != 32) {\n    throw new IllegalArgumentException(\"AES-256 key must decode to 32 bytes, got \" + keyBytes.length);\n}","typeGuard":null,"tryCatchPattern":"try {\n    factory.apply(config);\n} catch (OptionValidationException e) {\n    log.error(\"secret_key length invalid: {}\", e.getMessage());\n}","preventionTips":["Always generate 32-byte keys (`openssl rand -base64 32`).","Verify with `echo <key> | base64 -d | wc -c` before deploying.","Synchronize key changes across sender and receiver configs simultaneously."],"tags":["config","validation","aes-256","key-length"],"backgroundTag":"invalid-config-value","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}