{"record":{"id":"cb4261690dc15b37","repo":"gofiber/fiber","slug":"csrf-unexpected-value-type-t-in-storage","errorCode":null,"errorMessage":"csrf: unexpected value type %T in storage","messagePattern":"csrf: unexpected value type %T in storage","errorType":"http","errorClass":null,"httpStatus":500,"severity":"error","filePath":"middleware/csrf/storage_manager.go","lineNumber":48,"sourceCode":"\t\tstorageManager.memory = memory.New()\n\t}\n\treturn storageManager\n}\n\n// get raw data from storage or memory\nfunc (m *storageManager) getRaw(ctx context.Context, key string) ([]byte, error) {\n\tif m.storage != nil {\n\t\traw, err := m.storage.GetWithContext(ctx, key)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"csrf: failed to get value from storage: %w\", err)\n\t\t}\n\t\treturn raw, nil\n\t}\n\n\tif value := m.memory.Get(key); value != nil {\n\t\traw, ok := value.([]byte)\n\t\tif !ok {\n\t\t\treturn nil, fmt.Errorf(\"csrf: unexpected value type %T in storage\", value)\n\t\t}\n\t\treturn raw, nil\n\t}\n\n\treturn nil, nil\n}\n\n// set data to storage or memory\nfunc (m *storageManager) setRaw(ctx context.Context, key string, raw []byte, exp time.Duration) error {\n\tif m.storage != nil {\n\t\tif err := m.storage.SetWithContext(ctx, key, raw, exp); err != nil {\n\t\t\treturn fmt.Errorf(\"csrf: failed to store key %q: %w\", m.logKey(key), err)\n\t\t}\n\t\treturn nil\n\t}\n\n\tm.memory.Set(key, raw, exp)\n\treturn nil","sourceCodeStart":30,"sourceCodeEnd":66,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/storage_manager.go#L30-L66","documentation":"Returned by the in-memory branch of storageManager.getRaw when memory.Get returns a value whose type assertion to []byte fails. The CSRF storage manager only stores []byte via setRaw, so a non-[]byte value indicates shared memory, aliasing, or a defect.","triggerScenarios":"In-memory CSRF mode (cfg.Storage nil) where memory.Get(tokenKey) returns a non-[]byte value. Requires external interference with the memory store or a programming error.","commonSituations":"Not reachable in correct usage. Could occur if the memory.Storage is shared with other code writing non-[]byte values, or in tests that pre-seed the store incorrectly. Treat as a defect signal.","solutions":["Ensure the CSRF memory.Storage is not shared with other writers.","Each Fiber app should own its CSRF middleware and its memory store.","Audit test fixtures that directly populate memory.Storage.","Report as a bug if reproduced in isolation."],"exampleFix":null,"handlingStrategy":"type-guard","validationCode":null,"typeGuard":"func assertCsrfRawStored(s *memory.Storage, key string) error {\n    v := s.Get(key)\n    if v == nil {\n        return nil\n    }\n    if _, ok := v.([]byte); !ok {\n        return fmt.Errorf(\"unexpected type %T stored under csrf key\", v)\n    }\n    return nil\n}","tryCatchPattern":"if value := m.memory.Get(key); value != nil {\n    raw, ok := value.([]byte)\n    if !ok {\n        log.Error(\"csrf memory type violation:\", fmt.Sprintf(\"%T\", value))\n        m.memory.Delete(key)\n        return nil, nil // treat as absent\n    }\n    return raw, nil\n}","preventionTips":["Do not share the CSRF memory.Storage with other writers.","One CSRF middleware instance per app.","Keep test fixtures type-consistent with setRaw."],"tags":["csrf","type-assertion","memory","invariant","go","fiber"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}