{"record":{"id":"df987c2a67d309e5","repo":"gofiber/fiber","slug":"cors-invalid-origin-format-after-normalization","errorCode":null,"errorMessage":"[CORS] Invalid origin format after normalization:","messagePattern":"\\[CORS\\] Invalid origin format after normalization:","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/cors/cors.go","lineNumber":77,"sourceCode":"\n\t// Validate and normalize static AllowOrigins\n\tallowAllOrigins := len(cfg.AllowOrigins) == 0 && cfg.AllowOriginsFunc == nil\n\tfor _, origin := range cfg.AllowOrigins {\n\t\tif origin == \"*\" {\n\t\t\tallowAllOrigins = true\n\t\t\tbreak\n\t\t}\n\n\t\ttrimmedOrigin := utils.TrimSpace(origin)\n\t\tif before, after, found := strings.Cut(trimmedOrigin, \"://*.\"); found {\n\t\t\twithoutWildcard := before + \"://\" + after\n\t\t\tisValid, normalizedOrigin := normalizeOrigin(withoutWildcard)\n\t\t\tif !isValid {\n\t\t\t\tpanic(\"[CORS] Invalid origin format in configuration: \" + maskValue(trimmedOrigin))\n\t\t\t}\n\t\t\tscheme, host, ok := strings.Cut(normalizedOrigin, \"://\")\n\t\t\tif !ok {\n\t\t\t\tpanic(\"[CORS] Invalid origin format after normalization:\" + maskValue(trimmedOrigin))\n\t\t\t}\n\t\t\tsd := subdomain{prefix: scheme + \"://\", suffix: host}\n\t\t\tallowSubOrigins = append(allowSubOrigins, sd)\n\t\t} else {\n\t\t\tisValid, normalizedOrigin := normalizeOrigin(trimmedOrigin)\n\t\t\tif !isValid {\n\t\t\t\tpanic(\"[CORS] Invalid origin format in configuration: \" + maskValue(trimmedOrigin))\n\t\t\t}\n\t\t\tallowOrigins[normalizedOrigin] = struct{}{}\n\t\t}\n\t}\n\n\t// Validate CORS credentials configuration\n\tif cfg.AllowCredentials && allowAllOrigins {\n\t\tpanic(\"[CORS] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '*'. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting.\")\n\t}\n\n\t// Warn if allowAllOrigins is set to true and AllowOriginsFunc is defined","sourceCodeStart":59,"sourceCodeEnd":95,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/cors/cors.go#L59-L95","documentation":"A defensive fallback inside the CORS wildcard-subdomain branch: after normalizeOrigin succeeded on the de-wildcarded origin, strings.Cut(normalizedOrigin, \"://\") returned !ok — meaning the normalized origin somehow has no '://' separator. normalizeOrigin constructs its return as scheme+\"://\"+host, so reaching this panic indicates either a future regression in normalizeOrigin or a non-standard scheme/host shape; it should be unreachable for well-formed inputs.","triggerScenarios":"Effectively unreachable through normal config. Could surface only if normalizeOrigin is modified to return a valid flag without the scheme separator, or if a custom build patches the CORS utils. Any real occurrence is a bug in the library, not in user config.","commonSituations":"Vendoring/forking fiber and altering normalizeOrigin to emit a host-only normalized string; upgrading to a patch level that introduced a regression in cors/utils.go.","solutions":["Report the issue to gofiber/fiber with the exact origin that triggered it; include the fiber version.","If running a fork, restore normalizeOrigin to return scheme+\"://\"+host on the valid path.","As a workaround, restate the same origin without the '://*.' wildcard form (use a literal origin or AllowOriginsFunc)."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// This panic is defensive/near-unreachable for well-formed inputs.\n// Validate at the same boundary as 270/272; if normalizeOrigin returns valid\n// but lacks '://', report the fiber version to maintainers.\nfunc normalizedHasScheme(o string) bool {\n    _, ok := strings.Cut(o, \"://\")\n    return ok\n}","typeGuard":null,"tryCatchPattern":"defer func() {\n    if r := recover(); r != nil {\n        log.Fatalf(\"CORS normalization invariant violated (report to fiber): %v\", r)\n    }\n}()\ncors.New(cfg)","preventionTips":["Pin a known-good fiber release; re-test CORS config after upgrades.","If vendoring/forking, do not modify normalizeOrigin to drop the scheme separator.","Treat any hit of this branch as a library bug, not a config bug."],"tags":["middleware","cors","config","defensive","unreachable","startup"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}