gofiber/fiber · error

csrf: failed to store key

Error message

csrf: failed to store key %q: %w

What it means

Returned by storageManager.setRaw when the external Storage's SetWithContext fails while persisting a CSRF token. This is the storage-driver-level failure that bubbles up as error 152 during token creation/extension.

Solutions

  1. Inspect the wrapped error to identify capacity/network/permission cause.
  2. Verify Storage credentials have SET and the backend has free capacity.
  3. Tune write timeout and connection pool size; confirm the backend supports the configured IdleTimeout expiration semantics.
  4. If using a custom Storage impl, ensure SetWithContext only errors on genuine failures, not on routine operations.

Example fix

// before: token issuance fails opaquely when storage is unavailable
if err := m.storage.SetWithContext(ctx, key, raw, exp); err != nil {
    return fmt.Errorf("csrf: failed to store key %q: %w", m.logKey(key), err)
}

// after: distinguish capacity vs transient and degrade cleanly
if err := m.storage.SetWithContext(ctx, key, raw, exp); err != nil {
    if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
        return err
    }
    log.Error("csrf token store failed:", err)
    return err // caller decides fail-open vs fail-closed
}
Defensive patterns

Strategy: retry

Validate before calling

func validateCsrfSet(ctx context.Context, s fiber.Storage) error {
    return s.SetWithContext(ctx, "__csrf_set__", []byte("x"), time.Second)
}

Try / catch

if err := m.storage.SetWithContext(ctx, key, raw, exp); err != nil {
    if errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) {
        return err
    }
    log.Error("csrf token store failed:", err)
    return err // caller returns 503 to client
}

Prevention

When it happens

Trigger: CSRF token set against cfg.Storage where Storage.SetWithContext errors: backend down, write timeout, quota exceeded, ACL missing SET, context cancellation.

Common situations: Redis at maxmemory, storage outage during token issuance, ACL misconfiguration, connection pool exhaustion under load, custom Storage impl returning errors on Set.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/56786654b9639783. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/storage_manager.go:60

		return raw, nil
	}

	if value := m.memory.Get(key); value != nil {
		raw, ok := value.([]byte)
		if !ok {
			return nil, fmt.Errorf("csrf: unexpected value type %T in storage", value)
		}
		return raw, nil
	}

	return nil, nil
}

// set data to storage or memory
func (m *storageManager) setRaw(ctx context.Context, key string, raw []byte, exp time.Duration) error {
	if m.storage != nil {
		if err := m.storage.SetWithContext(ctx, key, raw, exp); err != nil {
			return fmt.Errorf("csrf: failed to store key %q: %w", m.logKey(key), err)
		}
		return nil
	}

	m.memory.Set(key, raw, exp)
	return nil
}

// delete data from storage or memory
func (m *storageManager) delRaw(ctx context.Context, key string) error {
	if m.storage != nil {
		if err := m.storage.DeleteWithContext(ctx, key); err != nil {
			return fmt.Errorf("csrf: failed to delete key %q: %w", m.logKey(key), err)
		}
		return nil
	}

	m.memory.Delete(key)

View on GitHub (pinned to a105acad6c)