{"record":{"id":"aa0e060b513773da","repo":"gofiber/fiber","slug":"basicauth-charset-must-be-utf-8","errorCode":null,"errorMessage":"basicauth: charset must be UTF-8","messagePattern":"basicauth: charset must be UTF-8","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/basicauth/config.go","lineNumber":145,"sourceCode":"\tif cfg.Next == nil {\n\t\tcfg.Next = ConfigDefault.Next\n\t}\n\n\tif cfg.Users == nil {\n\t\tcfg.Users = ConfigDefault.Users\n\t}\n\n\tif cfg.Realm == \"\" {\n\t\tcfg.Realm = ConfigDefault.Realm\n\t}\n\n\tswitch {\n\tcase cfg.Charset == \"\":\n\t\tcfg.Charset = ConfigDefault.Charset\n\tcase utils.EqualFold(cfg.Charset, \"UTF-8\"):\n\t\tcfg.Charset = \"UTF-8\"\n\tdefault:\n\t\tpanic(\"basicauth: charset must be UTF-8\")\n\t}\n\n\tif cfg.HeaderLimit <= 0 {\n\t\tcfg.HeaderLimit = ConfigDefault.HeaderLimit\n\t}\n\n\tif cfg.Authorizer == nil {\n\t\tverifiers, dummyVerify, err := buildVerifiers(cfg.Users)\n\t\tif err != nil {\n\t\t\tpanic(err)\n\t\t}\n\t\tcfg.Authorizer = func(user, pass string, _ fiber.Ctx) bool {\n\t\t\tverify, ok := verifiers[user]\n\t\t\tif !ok {\n\t\t\t\tverify = dummyVerify\n\t\t\t}\n\t\t\tres := verify(pass)\n\t\t\treturn ok && res","sourceCodeStart":127,"sourceCodeEnd":163,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/basicauth/config.go#L127-L163","documentation":"The basicauth middleware only allows UTF-8 (case-insensitively) as the WWW-Authenticate realm charset; an explicit non-empty Charset that is not UTF-8 is rejected because Basic auth credentials are bytes decoded per the realm charset and any other value would corrupt or misrepresent credential handling. Empty Charset defaults to UTF-8 (ConfigDefault.Charset).","triggerScenarios":"Calling basicauth.New(basicauth.Config{ Charset: \"ISO-8859-1\" }) (or \"utf8\", \"ascii\", \"UTF-16\", any non-empty non-UTF-8 value). Empty string and case variants of \"UTF-8\" are accepted/normalized.","commonSituations":"Copy-pasting a config from an old example that used Latin-1; setting Charset based on an environment variable that resolves to a different encoding name; typo like \"UTF8 \" (trailing space) — note this is NOT trimmed and will panic because utils.EqualFold(\"UTF8 \", \"UTF-8\") is false.","solutions":["Set Config.Charset to \"\" (let it default to UTF-8) or exactly \"UTF-8\".","Trim and case-normalize any externally-supplied charset value before assigning it: strings.TrimSpace(strings.ToUpper(v)) == \"UTF-8\".","Remove the Charset field entirely from your Config literal."],"exampleFix":"// before\nbasicauth.New(basicauth.Config{ Charset: \"ISO-8859-1\" })\n// after\nbasicauth.New(basicauth.Config{ /* Charset omitted; defaults to UTF-8 */ })","handlingStrategy":"validation","validationCode":"if cfg.Charset != \"\" && !utils.EqualFold(cfg.Charset, \"UTF-8\") {\n    return fmt.Errorf(\"basicauth charset must be UTF-8, got %q\", cfg.Charset)\n}\n// or simply normalize:\nif cfg.Charset == \"\" || utils.EqualFold(cfg.Charset, \"UTF-8\") {\n    cfg.Charset = \"UTF-8\"\n} else {\n    return fmt.Errorf(\"unsupported charset %q\", cfg.Charset)\n}","typeGuard":null,"tryCatchPattern":"defer func() {\n    if r := recover(); r != nil {\n        log.Fatalf(\"basicauth config invalid: %v\", r)\n    }\n}()\nbasicauth.New(cfg)","preventionTips":["Omit Charset from basicauth.Config entirely; it defaults to UTF-8.","When loading Charset from env/config, trim whitespace and reject anything that is not case-insensitive 'UTF-8'.","Avoid trailing spaces/typos like \"UTF8 \" or \"utf-8 \\n\" — they are not trimmed and will panic."],"tags":["middleware","basicauth","config","validation","startup"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}