gofiber/fiber · error
[CORS] Invalid origin format after normalization:
Error message
[CORS] Invalid origin format after normalization:
What it means
A defensive fallback inside the CORS wildcard-subdomain branch: after normalizeOrigin succeeded on the de-wildcarded origin, strings.Cut(normalizedOrigin, "://") returned !ok — meaning the normalized origin somehow has no '://' separator. normalizeOrigin constructs its return as scheme+"://"+host, so reaching this panic indicates either a future regression in normalizeOrigin or a non-standard scheme/host shape; it should be unreachable for well-formed inputs.
Solutions
- Report the issue to gofiber/fiber with the exact origin that triggered it; include the fiber version.
- If running a fork, restore normalizeOrigin to return scheme+"://"+host on the valid path.
- As a workaround, restate the same origin without the '://*.' wildcard form (use a literal origin or AllowOriginsFunc).
Defensive patterns
Strategy: validation
Validate before calling
// This panic is defensive/near-unreachable for well-formed inputs.
// Validate at the same boundary as 270/272; if normalizeOrigin returns valid
// but lacks '://', report the fiber version to maintainers.
func normalizedHasScheme(o string) bool {
_, ok := strings.Cut(o, "://")
return ok
} Try / catch
defer func() {
if r := recover(); r != nil {
log.Fatalf("CORS normalization invariant violated (report to fiber): %v", r)
}
}()
cors.New(cfg) Prevention
- Pin a known-good fiber release; re-test CORS config after upgrades.
- If vendoring/forking, do not modify normalizeOrigin to drop the scheme separator.
- Treat any hit of this branch as a library bug, not a config bug.
When it happens
Trigger: Effectively unreachable through normal config. Could surface only if normalizeOrigin is modified to return a valid flag without the scheme separator, or if a custom build patches the CORS utils. Any real occurrence is a bug in the library, not in user config.
Common situations: Vendoring/forking fiber and altering normalizeOrigin to emit a host-only normalized string; upgrading to a patch level that introduced a regression in cors/utils.go.
Related errors
- [CORS] Invalid origin format in configuration:
- basicauth: charset must be UTF-8
- [CORS] Configuration error: When 'AllowCredentials' is set…
- [CSRF] Invalid origin format in configuration:
- fiber: encrypt cookie middleware requires key
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/df987c2a67d309e5.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/cors/cors.go:77
// Validate and normalize static AllowOrigins
allowAllOrigins := len(cfg.AllowOrigins) == 0 && cfg.AllowOriginsFunc == nil
for _, origin := range cfg.AllowOrigins {
if origin == "*" {
allowAllOrigins = true
break
}
trimmedOrigin := utils.TrimSpace(origin)
if before, after, found := strings.Cut(trimmedOrigin, "://*."); found {
withoutWildcard := before + "://" + after
isValid, normalizedOrigin := normalizeOrigin(withoutWildcard)
if !isValid {
panic("[CORS] Invalid origin format in configuration: " + maskValue(trimmedOrigin))
}
scheme, host, ok := strings.Cut(normalizedOrigin, "://")
if !ok {
panic("[CORS] Invalid origin format after normalization:" + maskValue(trimmedOrigin))
}
sd := subdomain{prefix: scheme + "://", suffix: host}
allowSubOrigins = append(allowSubOrigins, sd)
} else {
isValid, normalizedOrigin := normalizeOrigin(trimmedOrigin)
if !isValid {
panic("[CORS] Invalid origin format in configuration: " + maskValue(trimmedOrigin))
}
allowOrigins[normalizedOrigin] = struct{}{}
}
}
// Validate CORS credentials configuration
if cfg.AllowCredentials && allowAllOrigins {
panic("[CORS] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '*'. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting.")
}
// Warn if allowAllOrigins is set to true and AllowOriginsFunc is definedView on GitHub (pinned to a105acad6c)