{"record":{"id":"9582c4c437cfda3d","repo":"gofiber/fiber","slug":"fiber-keyauth-unsupported-error-token","errorCode":null,"errorMessage":"fiber: keyauth unsupported error token","messagePattern":"fiber: keyauth unsupported error token","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/keyauth/config.go","lineNumber":136,"sourceCode":"\tif cfg.Realm == \"\" {\n\t\tcfg.Realm = ConfigDefault.Realm\n\t}\n\tif cfg.SuccessHandler == nil {\n\t\tcfg.SuccessHandler = ConfigDefault.SuccessHandler\n\t}\n\tif cfg.ErrorHandler == nil {\n\t\tcfg.ErrorHandler = ConfigDefault.ErrorHandler\n\t}\n\n\tif len(getAuthSchemes(cfg.Extractor)) == 0 && cfg.Challenge == \"\" {\n\t\tcfg.Challenge = fmt.Sprintf(\"ApiKey realm=%q\", cfg.Realm)\n\t}\n\n\tif cfg.Error != \"\" {\n\t\tswitch cfg.Error {\n\t\tcase ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope:\n\t\tdefault:\n\t\t\tpanic(\"fiber: keyauth unsupported error token\")\n\t\t}\n\t}\n\tif cfg.ErrorDescription != \"\" && cfg.Error == \"\" {\n\t\tpanic(\"fiber: keyauth error_description requires error\")\n\t}\n\tif cfg.ErrorURI != \"\" {\n\t\tif cfg.Error == \"\" {\n\t\t\tpanic(\"fiber: keyauth error_uri requires error\")\n\t\t}\n\t\tif u, err := url.Parse(cfg.ErrorURI); err != nil || !u.IsAbs() {\n\t\t\tpanic(\"fiber: keyauth error_uri must be absolute\")\n\t\t}\n\t}\n\tif cfg.Error == ErrorInsufficientScope {\n\t\tif cfg.Scope == \"\" {\n\t\t\tpanic(\"fiber: keyauth insufficient_scope requires scope\")\n\t\t}\n\t\tfor scope := range strings.SplitSeq(cfg.Scope, \" \") {","sourceCodeStart":118,"sourceCodeEnd":154,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/keyauth/config.go#L118-L154","documentation":"keyauth validates Config.Error against the RFC 6750 Bearer error vocabulary. Only three values are allowed: invalid_request, invalid_token, insufficient_scope (the package constants ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope). Any other string panics, because the WWW-Authenticate challenge must use the standardized error codes or clients cannot interpret them.","triggerScenarios":"Setting Config.Error to a free-form string such as \"bad_key\", \"expired\", or a typo like \"invalid-token\" (hyphen instead of underscore). Also triggered by building the value dynamically and producing an empty-but-non-empty-after-trim result, or a custom code.","commonSituations":"Hand-writing the error code instead of using the package constants; copy-pasting from an OAuth error table that uses different casing/punctuation; version skew if the constants were renamed and code still hardcodes strings.","solutions":["Use the package constants: keyauth.ErrorInvalidToken, keyauth.ErrorInvalidRequest, or keyauth.ErrorInsufficientScope.","Leave Error empty if you do not need an RFC 6750 challenge (the middleware works without it).","If the value comes from config, validate it against the three allowed strings at load time."],"exampleFix":"// before\napp.Use(keyauth.New(keyauth.Config{\n    Validator: v,\n    Error:     \"invalid-token\",\n}))\n\n// after\napp.Use(keyauth.New(keyauth.Config{\n    Validator: v,\n    Error:     keyauth.ErrorInvalidToken,\n}))","handlingStrategy":"validation","validationCode":"var allowedErrors = map[string]struct{}{\n    keyauth.ErrorInvalidRequest:    {},\n    keyauth.ErrorInvalidToken:      {},\n    keyauth.ErrorInsufficientScope: {},\n}\nif cfg.Error != \"\" {\n    if _, ok := allowedErrors[cfg.Error]; !ok {\n        log.Fatalf(\"unsupported keyauth Error: %q\", cfg.Error)\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always reference the package constants instead of hardcoding the error strings.","Validate Config.Error against the allowed set at the config loader.","Leave Error empty unless you specifically need an RFC 6750 challenge."],"tags":["keyauth","oauth","rfc-6750","config","auth","startup-panic"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}