{"record":{"id":"dfe2e8c0248d74cc","repo":"gofiber/fiber","slug":"csrf-failed-to-delete-key-q-w","errorCode":null,"errorMessage":"csrf: failed to delete key %q: %w","messagePattern":"csrf: failed to delete key %q: %w","errorType":"http","errorClass":null,"httpStatus":500,"severity":"warning","filePath":"middleware/csrf/storage_manager.go","lineNumber":73,"sourceCode":"\n// set data to storage or memory\nfunc (m *storageManager) setRaw(ctx context.Context, key string, raw []byte, exp time.Duration) error {\n\tif m.storage != nil {\n\t\tif err := m.storage.SetWithContext(ctx, key, raw, exp); err != nil {\n\t\t\treturn fmt.Errorf(\"csrf: failed to store key %q: %w\", m.logKey(key), err)\n\t\t}\n\t\treturn nil\n\t}\n\n\tm.memory.Set(key, raw, exp)\n\treturn nil\n}\n\n// delete data from storage or memory\nfunc (m *storageManager) delRaw(ctx context.Context, key string) error {\n\tif m.storage != nil {\n\t\tif err := m.storage.DeleteWithContext(ctx, key); err != nil {\n\t\t\treturn fmt.Errorf(\"csrf: failed to delete key %q: %w\", m.logKey(key), err)\n\t\t}\n\t\treturn nil\n\t}\n\n\tm.memory.Delete(key)\n\treturn nil\n}\n\nfunc (m *storageManager) logKey(key string) string {\n\tif m.shouldRedactKeys {\n\t\treturn redactedKey\n\t}\n\treturn key\n}\n","sourceCodeStart":55,"sourceCodeEnd":88,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/storage_manager.go#L55-L88","documentation":"Returned by storageManager.delRaw when the external Storage's DeleteWithContext fails while removing a CSRF token. This is the storage-driver-level failure that bubbles up as error 153 during token invalidation.","triggerScenarios":"CSRF token deletion against cfg.Storage where Storage.DeleteWithContext errors: backend down, ACL missing DEL, network error, context cancellation, failover mid-delete.","commonSituations":"Redis ACL without DEL permission, storage transient outage during logout, connection errors, custom Storage impl returning errors on Delete.","solutions":["Inspect the wrapped error for permission/connectivity/cancellation.","Ensure Storage credentials grant DEL permission.","Keep IdleTimeout short so a failed delete self-heals via TTL.","Log and continue — do not block logout on a best-effort token delete."],"exampleFix":"// before\nif err := m.storage.DeleteWithContext(ctx, key); err != nil {\n    return fmt.Errorf(\"csrf: failed to delete key %q: %w\", m.logKey(key), err)\n}\n\n// after: best-effort, TTL backstops\nif err := m.storage.DeleteWithContext(ctx, key); err != nil {\n    log.Warn(\"csrf token delete failed; TTL will expire it:\", err)\n}\nreturn nil","handlingStrategy":"fallback","validationCode":"func validateCsrfDel(ctx context.Context, s fiber.Storage) error {\n    _ = s.SetWithContext(ctx, \"__csrf_d__\", []byte(\"x\"), time.Second)\n    return s.DeleteWithContext(ctx, \"__csrf_d__\")\n}","typeGuard":null,"tryCatchPattern":"if err := m.storage.DeleteWithContext(ctx, key); err != nil {\n    log.Warn(\"csrf token delete failed; TTL will expire it:\", err)\n}\nreturn nil","preventionTips":["Grant DEL permission on Storage credentials.","Keep IdleTimeout short so failed deletes self-heal.","Do not block logout on a best-effort token delete."],"tags":["csrf","storage","network","delete","auth","go","fiber"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}