gofiber/fiber · error

csrf: failed to get value from storage

Error message

csrf: failed to get value from storage: %w

What it means

Returned by storageManager.getRaw (the lower-level call beneath getRawFromStorage) when the external Storage's GetWithContext errors reading a CSRF token. This is the storage-driver-level failure that surfaces upward as error 151.

Solutions

  1. Examine the wrapped error to pinpoint the driver-level cause.
  2. Verify Storage connectivity/auth and connection pool configuration.
  3. If using a custom Storage implementation, ensure GetWithContext distinguishes 'not found' (return nil,nil) from genuine errors.
  4. Tune timeouts and pool size; add health checks/circuit breaking.

Example fix

// Custom Storage impl: never return an error for a missing key.
// before
func (s *MyStore) GetWithContext(ctx context.Context, key string) ([]byte, error) {
    v, ok := s.m.Load(key)
    if !ok {
        return nil, errors.New("not found") // WRONG — surfaces as 154
    }
    return v.([]byte), nil
}

// after
func (s *MyStore) GetWithContext(ctx context.Context, key string) ([]byte, error) {
    v, ok := s.m.Load(key)
    if !ok {
        return nil, nil // correct: nil value signals absence
    }
    return v.([]byte), nil
}
Defensive patterns

Strategy: retry

Validate before calling

// Custom Storage impls MUST return (nil, nil) for missing keys.
// Validate this contract before deploying.
func validateStorageContract(ctx context.Context, s fiber.Storage) error {
    got, err := s.GetWithContext(ctx, "__nonexistent__")
    if err != nil {
        return fmt.Errorf("GetWithContext must not error on absent key: %w", err)
    }
    if got != nil {
        return fmt.Errorf("GetWithContext must return nil value for absent key")
    }
    return nil
}

Try / catch

raw, err := m.storage.GetWithContext(ctx, key)
if err != nil {
    if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
        return nil, err
    }
    log.Error("csrf storage get failed; treating as absent (reject token):", err)
    return nil, nil // caller will reject the token
}

Prevention

When it happens

Trigger: CSRF token verification with cfg.Storage set; Storage.GetWithContext returns a non-nil error for the token key. Driver/connection/protocol-level failure in the configured Storage implementation.

Common situations: Redis/storage unreachable, auth failure, pool exhaustion, TLS errors, context cancellation, custom Storage impl returning errors for missing keys instead of (nil,nil).

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/71dc44d88c381fe0. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/storage_manager.go:40

	storageManager := &storageManager{
		shouldRedactKeys: shouldRedactKeys,
	}
	if storage != nil {
		// Use provided storage if provided
		storageManager.storage = storage
	} else {
		// Fallback to memory storage
		storageManager.memory = memory.New()
	}
	return storageManager
}

// get raw data from storage or memory
func (m *storageManager) getRaw(ctx context.Context, key string) ([]byte, error) {
	if m.storage != nil {
		raw, err := m.storage.GetWithContext(ctx, key)
		if err != nil {
			return nil, fmt.Errorf("csrf: failed to get value from storage: %w", err)
		}
		return raw, nil
	}

	if value := m.memory.Get(key); value != nil {
		raw, ok := value.([]byte)
		if !ok {
			return nil, fmt.Errorf("csrf: unexpected value type %T in storage", value)
		}
		return raw, nil
	}

	return nil, nil
}

// set data to storage or memory
func (m *storageManager) setRaw(ctx context.Context, key string, raw []byte, exp time.Duration) error {
	if m.storage != nil {

View on GitHub (pinned to a105acad6c)