{"record":{"id":"b091a26dd75fcdc5","repo":"JuliusBrussee/caveman","slug":"envelope-encode-scope-w","errorCode":null,"errorMessage":"envelope: encode scope: %w","messagePattern":"envelope: encode scope: %w","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/envelope/envelope.go","lineNumber":185,"sourceCode":"\nfunc scopeAAD(scope Scope) ([]byte, string, error) {\n\tscope.OrganizationID = strings.TrimSpace(scope.OrganizationID)\n\tscope.ProjectID = strings.TrimSpace(scope.ProjectID)\n\tscope.Kind = strings.TrimSpace(scope.Kind)\n\tif scope.OrganizationID == \"\" {\n\t\treturn nil, \"\", fmt.Errorf(\"envelope: organization scope is required\")\n\t}\n\tif scope.Kind == \"\" {\n\t\treturn nil, \"\", fmt.Errorf(\"envelope: object kind is required\")\n\t}\n\taad, err := json.Marshal(struct {\n\t\tVersion        int    `json:\"version\"`\n\t\tOrganizationID string `json:\"organization_id\"`\n\t\tProjectID      string `json:\"project_id\"`\n\t\tKind           string `json:\"kind\"`\n\t}{2, scope.OrganizationID, scope.ProjectID, scope.Kind})\n\tif err != nil {\n\t\treturn nil, \"\", fmt.Errorf(\"envelope: encode scope: %w\", err)\n\t}\n\tsum := sha256.Sum256(aad)\n\treturn aad, hex.EncodeToString(sum[:]), nil\n}\n","sourceCodeStart":167,"sourceCodeEnd":190,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/envelope/envelope.go#L167-L190","documentation":"json.Marshal of the scope struct (version, organization_id, project_id, kind) failed while building the AAD for envelope encryption. This is essentially unreachable in practice — the struct contains only an int and three strings, which always marshal — so it exists purely to satisfy error handling in the fail-closed design.","triggerScenarios":"Calling SealForScope or OpenForScope when json.Marshal errors on the fixed scope struct; under current Go semantics this cannot occur for these field types, but the wrapped error would carry the json package's message.","commonSituations":"Not seen in practice; only a hypothetical broken encoding.Malformed or exotic Go runtime could theoretically trigger it.","solutions":["Treat it as an internal invariant violation; the wrapped json error should be reported upstream","If it ever reproduces, verify the Go toolchain/encoding/json version for anomalies","No caller-side fix exists — the input struct is fixed by the library","Retry after confirming non-degenerate Scope values is unnecessary; escalate as a bug"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"_, _, err := /* SealForScope/OpenForScope */\nif err != nil && strings.Contains(err.Error(), \"encode scope\") {\n    // internal invariant violation: report as a bug with the wrapped json error\n}","preventionTips":["Not caller-preventable; report to library maintainers if observed"],"tags":["go","json","internal-error"],"backgroundTag":"json-marshal-failed","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}