{"record":{"id":"af9178e2ba2161c3","repo":"gofiber/fiber","slug":"failed-to-base64-decode-value-w","errorCode":null,"errorMessage":"failed to base64-decode value: %w","messagePattern":"failed to base64-decode value: %w","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/encryptcookie/utils.go","lineNumber":70,"sourceCode":"\tgcm, err := cipher.NewGCMWithRandomNonce(block)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to create GCM mode: %w\", err)\n\t}\n\n\tciphertext := gcm.Seal(nil, nil, []byte(value), []byte(name))\n\treturn base64.StdEncoding.EncodeToString(ciphertext), nil\n}\n\n// DecryptCookie Decrypts a cookie value with specific encryption key\nfunc DecryptCookie(name, value, key string) (string, error) {\n\tkeyDecoded, err := decodeKey(key)\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\n\tenc, err := base64.StdEncoding.DecodeString(value)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to base64-decode value: %w\", err)\n\t}\n\n\tblock, err := aes.NewCipher(keyDecoded)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to create AES cipher: %w\", err)\n\t}\n\n\tgcm, err := cipher.NewGCMWithRandomNonce(block)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to create GCM mode: %w\", err)\n\t}\n\n\tif len(enc) < gcm.NonceSize()+gcm.Overhead() {\n\t\treturn \"\", ErrInvalidEncryptedValue\n\t}\n\n\tplaintext, err := gcm.Open(nil, nil, enc, []byte(name))\n\tif err != nil {","sourceCodeStart":52,"sourceCodeEnd":88,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/encryptcookie/utils.go#L52-L88","documentation":"Returned by DecryptCookie when the incoming cookie value is not valid base64 (StdEncoding). DecryptCookie first base64-decodes the stored value before attempting AES-GCM decryption, so any non-base64 payload fails here. The wrapped %w carries encoding/base64's CorruptInputError, which reports the byte offset of corruption.","triggerScenarios":"Calling encryptcookie.DecryptCookie(name, value, key) where value is not a valid base64 string — e.g. a tampered cookie, a cookie set by a different library, a URL-safe base64 payload, or a value with whitespace/newlines that StdEncoding rejects.","commonSituations":"Switching from URLSafe base64 to standard base64 (or vice versa), clients truncating long cookies, proxies stripping '=' padding, rotating the encryption scheme without invalidating old cookies, or decrypting a plaintext cookie set by middleware that does not use EncryptCookie.","solutions":["Verify the cookie was produced by EncryptCookie with the same base64 (StdEncoding) variant.","Check for proxy/gateway re-encoding of cookie values (URL-encoding, stripping padding).","If migrating encoding, clear/rotate old cookies so clients get fresh EncryptCookie output.","Log the raw value length and the CorruptInputError offset to pinpoint corruption."],"exampleFix":"// before\nplaintext, err := encryptcookie.DecryptCookie(name, c.Cookies(name), key)\n// after\nraw := c.Cookies(name)\nif _, bErr := base64.StdEncoding.DecodeString(raw); bErr != nil {\n    c.ClearCookie(name) // stale/tampered cookie; let the user re-auth\n    return c.Redirect(\"/login\")\n}\nplaintext, err := encryptcookie.DecryptCookie(name, raw, key)","handlingStrategy":"validation","validationCode":"if _, err := base64.StdEncoding.DecodeString(value); err != nil {\n    // not a valid EncryptCookie payload; treat as missing\n    return redirectToLogin()\n}","typeGuard":"func isStdBase64(s string) bool {\n    _, err := base64.StdEncoding.DecodeString(s)\n    return err == nil\n}","tryCatchPattern":"plain, err := encryptcookie.DecryptCookie(name, value, key)\nif err != nil {\n    c.ClearCookie(name)\n    return c.Redirect(\"/login\")\n}","preventionTips":["Always use EncryptCookie to produce values you later DecryptCookie.","Keep the same base64 variant (StdEncoding) across all environments.","On encoding migration, invalidate existing cookies."],"tags":["base64","encryptcookie","cookie","corrupt-input"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}