{"record":{"id":"d43dbc9255f8b9fc","repo":"gofiber/fiber","slug":"encryption-key-must-be-16-24-or-32-bytes","errorCode":null,"errorMessage":"encryption key must be 16, 24, or 32 bytes","messagePattern":"encryption key must be 16, 24, or 32 bytes","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/encryptcookie/utils.go","lineNumber":14,"sourceCode":"package encryptcookie\n\nimport (\n\t\"crypto/aes\"\n\t\"crypto/cipher\"\n\t\"crypto/rand\"\n\t\"encoding/base64\"\n\t\"errors\"\n\t\"fmt\"\n\t\"slices\"\n)\n\nvar (\n\tErrInvalidKeyLength      = errors.New(\"encryption key must be 16, 24, or 32 bytes\")\n\tErrInvalidEncryptedValue = errors.New(\"encrypted value is not valid\")\n)\n\n// decodeKey decodes the provided base64-encoded key and validates its length.\n// It returns the decoded key bytes or an error when invalid.\nfunc decodeKey(key string) ([]byte, error) {\n\tkeyDecoded, err := base64.StdEncoding.DecodeString(key)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to base64-decode key: %w\", err)\n\t}\n\n\tkeyLen := len(keyDecoded)\n\tif keyLen != 16 && keyLen != 24 && keyLen != 32 {\n\t\treturn nil, ErrInvalidKeyLength\n\t}\n\n\treturn keyDecoded, nil\n}","sourceCodeStart":1,"sourceCodeEnd":32,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/encryptcookie/utils.go#L1-L32","documentation":"Returned by middleware/encryptcookie.decodeKey when a base64-decoded key is not 16, 24, or 32 bytes (AES-128/192/256 key sizes). It is also panicked from the config default path (utils.go:100) when the package-level key fails validation. The lengths map directly to AES; anything else cannot create a cipher.","triggerScenarios":"Setting encryptcookie.Config.Key to a base64 string whose decoded length is not 16/24/32 bytes; using a raw passphrase instead of a key; a key generated for a different AES size; truncation or padding in the base64.","commonSituations":"Pasting a hex or ASCII password into Key instead of a base64-encoded random key; env var truncated; generating a key with the wrong byte length; rotating from a 16-byte to a 32-byte key but not updating the env on all instances.","solutions":["Generate a proper key: `openssl rand -base64 32` (32 bytes) and use that as Key.","Confirm the decoded length is exactly 16, 24, or 32 bytes; the error fires after base64 decode, not on the raw string length.","Keep the key consistent across all instances sharing encrypted cookies (same size and value).","If migrating key sizes, decrypt existing cookies with the old key and re-encrypt with the new one."],"exampleFix":"// before\nKey: \"my-secret-password\" // not a valid AES key\n// after\n// generated once: openssl rand -base64 32\nKey: \"cGFzc3dvcmRwYXNzd29yZHBhc3N3b3JkcGFzc3dvcmQ=\" // base64 of 32 bytes","handlingStrategy":"validation","validationCode":"func validEncryptKey(b64 string) error {\n    b, err := base64.StdEncoding.DecodeString(b64)\n    if err != nil { return err }\n    switch len(b) {\n    case 16, 24, 32: return nil\n    default: return encryptcookie.ErrInvalidKeyLength\n    }\n}","typeGuard":null,"tryCatchPattern":"if err := encryptcookie.ValidateKey(key); err != nil {\n    if errors.Is(err, encryptcookie.ErrInvalidKeyLength) {\n        // regenerate key with correct length before continuing\n    }\n    return err\n}","preventionTips":["Generate keys with `openssl rand -base64 32` and store in a secret manager.","Validate the key at startup; the default config path panics, so catch config errors early.","Keep key length and value identical across all instances sharing cookies."],"tags":["encryptcookie","crypto","config","cookies"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}