gofiber/fiber · critical

[CORS] Configuration error: When 'AllowCredentials' is set…

Error message

[CORS] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '*'. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting.

What it means

CORS rejects an insecure combination: AllowCredentials=true together with a wildcard ('allow all') origin policy. Returning 'Access-Control-Allow-Origin: *' (or reflecting any origin) while sending credentials violates the CORS spec and lets any site make authenticated cross-origin requests — a credential-leak vulnerability. allowAllOrigins is true when AllowOrigins contains '*' (or is empty with no AllowOriginsFunc).

Solutions

  1. List explicit origins in AllowOrigins (e.g. []string{"https://app.example.com"}) and keep AllowCredentials: true.
  2. Alternatively, keep the wildcard policy but set AllowCredentials: false (and do not send cookies).
  3. Use AllowOriginsFunc to dynamically allowlist known origins when credentials are required.

Example fix

// before
cors.New(cors.Config{
    AllowCredentials: true,
    AllowOrigins:     []string{"*"},
})
// after
cors.New(cors.Config{
    AllowCredentials: true,
    AllowOrigins:     []string{"https://app.example.com"},
})
Defensive patterns

Strategy: validation

Validate before calling

// Reject the credentials+wildcard combination before constructing the middleware.
allowAll := len(cfg.AllowOrigins) == 0 && cfg.AllowOriginsFunc == nil
for _, o := range cfg.AllowOrigins {
    if o == "*" { allowAll = true }
}
if cfg.AllowCredentials && allowAll {
    return errors.New("AllowCredentials cannot be combined with a wildcard/empty AllowOrigins")
}

Try / catch

defer func() {
    if r := recover(); r != nil {
        log.Fatalf("insecure CORS config: %v", r)
    }
}()
cors.New(cfg)

Prevention

When it happens

Trigger: cors.New(cors.Config{ AllowCredentials: true, AllowOrigins: []string{"*"} }) OR cors.New(cors.Config{ AllowCredentials: true /* AllowOrigins empty, AllowOriginsFunc nil */ }). Either makes allowAllOrigins true, which combined with AllowCredentials is fatal.

Common situations: Enabling cookies/JWT-in-cookies for a SPA and lazily setting AllowOrigins to '*'; leaving AllowOrigins empty (which means allow-all) while flipping AllowCredentials on; cargo-culting a permissive CORS config from a tutorial.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/4a55156abcc8d664. Report an issue: GitHub.

Appendix: source

Thrown at middleware/cors/cors.go:92

			}
			scheme, host, ok := strings.Cut(normalizedOrigin, "://")
			if !ok {
				panic("[CORS] Invalid origin format after normalization:" + maskValue(trimmedOrigin))
			}
			sd := subdomain{prefix: scheme + "://", suffix: host}
			allowSubOrigins = append(allowSubOrigins, sd)
		} else {
			isValid, normalizedOrigin := normalizeOrigin(trimmedOrigin)
			if !isValid {
				panic("[CORS] Invalid origin format in configuration: " + maskValue(trimmedOrigin))
			}
			allowOrigins[normalizedOrigin] = struct{}{}
		}
	}

	// Validate CORS credentials configuration
	if cfg.AllowCredentials && allowAllOrigins {
		panic("[CORS] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '*'. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting.")
	}

	// Warn if allowAllOrigins is set to true and AllowOriginsFunc is defined
	if allowAllOrigins && cfg.AllowOriginsFunc != nil {
		log.Warn("[CORS] 'AllowOrigins' is set to allow all origins, 'AllowOriginsFunc' will not be used.")
	}

	// Convert int to string
	maxAge := strconv.Itoa(cfg.MaxAge)

	// Return new handler
	return func(c fiber.Ctx) error {
		// Don't execute middleware if Next returns true
		if cfg.Next != nil && cfg.Next(c) {
			return c.Next()
		}

		// Get origin header preserving the original case for the response

View on GitHub (pinned to a105acad6c)