gofiber/fiber · error

[CORS] Invalid origin format after normalization:

Error message

[CORS] Invalid origin format after normalization:

What it means

A defensive fallback inside the CORS wildcard-subdomain branch: after normalizeOrigin succeeded on the de-wildcarded origin, strings.Cut(normalizedOrigin, "://") returned !ok — meaning the normalized origin somehow has no '://' separator. normalizeOrigin constructs its return as scheme+"://"+host, so reaching this panic indicates either a future regression in normalizeOrigin or a non-standard scheme/host shape; it should be unreachable for well-formed inputs.

Solutions

  1. Report the issue to gofiber/fiber with the exact origin that triggered it; include the fiber version.
  2. If running a fork, restore normalizeOrigin to return scheme+"://"+host on the valid path.
  3. As a workaround, restate the same origin without the '://*.' wildcard form (use a literal origin or AllowOriginsFunc).
Defensive patterns

Strategy: validation

Validate before calling

// This panic is defensive/near-unreachable for well-formed inputs.
// Validate at the same boundary as 270/272; if normalizeOrigin returns valid
// but lacks '://', report the fiber version to maintainers.
func normalizedHasScheme(o string) bool {
    _, ok := strings.Cut(o, "://")
    return ok
}

Try / catch

defer func() {
    if r := recover(); r != nil {
        log.Fatalf("CORS normalization invariant violated (report to fiber): %v", r)
    }
}()
cors.New(cfg)

Prevention

When it happens

Trigger: Effectively unreachable through normal config. Could surface only if normalizeOrigin is modified to return a valid flag without the scheme separator, or if a custom build patches the CORS utils. Any real occurrence is a bug in the library, not in user config.

Common situations: Vendoring/forking fiber and altering normalizeOrigin to emit a host-only normalized string; upgrading to a patch level that introduced a regression in cors/utils.go.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/df987c2a67d309e5. Report an issue: GitHub.

Appendix: source

Thrown at middleware/cors/cors.go:77

	// Validate and normalize static AllowOrigins
	allowAllOrigins := len(cfg.AllowOrigins) == 0 && cfg.AllowOriginsFunc == nil
	for _, origin := range cfg.AllowOrigins {
		if origin == "*" {
			allowAllOrigins = true
			break
		}

		trimmedOrigin := utils.TrimSpace(origin)
		if before, after, found := strings.Cut(trimmedOrigin, "://*."); found {
			withoutWildcard := before + "://" + after
			isValid, normalizedOrigin := normalizeOrigin(withoutWildcard)
			if !isValid {
				panic("[CORS] Invalid origin format in configuration: " + maskValue(trimmedOrigin))
			}
			scheme, host, ok := strings.Cut(normalizedOrigin, "://")
			if !ok {
				panic("[CORS] Invalid origin format after normalization:" + maskValue(trimmedOrigin))
			}
			sd := subdomain{prefix: scheme + "://", suffix: host}
			allowSubOrigins = append(allowSubOrigins, sd)
		} else {
			isValid, normalizedOrigin := normalizeOrigin(trimmedOrigin)
			if !isValid {
				panic("[CORS] Invalid origin format in configuration: " + maskValue(trimmedOrigin))
			}
			allowOrigins[normalizedOrigin] = struct{}{}
		}
	}

	// Validate CORS credentials configuration
	if cfg.AllowCredentials && allowAllOrigins {
		panic("[CORS] Configuration error: When 'AllowCredentials' is set to true, 'AllowOrigins' cannot contain a wildcard origin '*'. Please specify allowed origins explicitly or adjust 'AllowCredentials' setting.")
	}

	// Warn if allowAllOrigins is set to true and AllowOriginsFunc is defined

View on GitHub (pinned to a105acad6c)