gofiber/fiber · error
csrf: unexpected value type %T in storage
Error message
csrf: unexpected value type %T in storage
What it means
Returned by the in-memory branch of storageManager.getRaw when memory.Get returns a value whose type assertion to []byte fails. The CSRF storage manager only stores []byte via setRaw, so a non-[]byte value indicates shared memory, aliasing, or a defect.
Solutions
- Ensure the CSRF memory.Storage is not shared with other writers.
- Each Fiber app should own its CSRF middleware and its memory store.
- Audit test fixtures that directly populate memory.Storage.
- Report as a bug if reproduced in isolation.
Defensive patterns
Strategy: type-guard
Type guard
func assertCsrfRawStored(s *memory.Storage, key string) error {
v := s.Get(key)
if v == nil {
return nil
}
if _, ok := v.([]byte); !ok {
return fmt.Errorf("unexpected type %T stored under csrf key", v)
}
return nil
} Try / catch
if value := m.memory.Get(key); value != nil {
raw, ok := value.([]byte)
if !ok {
log.Error("csrf memory type violation:", fmt.Sprintf("%T", value))
m.memory.Delete(key)
return nil, nil // treat as absent
}
return raw, nil
} Prevention
- Do not share the CSRF memory.Storage with other writers.
- One CSRF middleware instance per app.
- Keep test fixtures type-consistent with setRaw.
When it happens
Trigger: In-memory CSRF mode (cfg.Storage nil) where memory.Get(tokenKey) returns a non-[]byte value. Requires external interference with the memory store or a programming error.
Common situations: Not reachable in correct usage. Could occur if the memory.Storage is shared with other code writing non-[]byte values, or in tests that pre-seed the store incorrectly. Treat as a defect signal.
Related errors
- cache: unexpected entry type %T for key
- cache: unexpected raw entry type %T for key
- csrf: failed to delete key
- csrf: failed to delete token from storage
- csrf: failed to fetch token from storage
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/cb4261690dc15b37.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/csrf/storage_manager.go:48
storageManager.memory = memory.New()
}
return storageManager
}
// get raw data from storage or memory
func (m *storageManager) getRaw(ctx context.Context, key string) ([]byte, error) {
if m.storage != nil {
raw, err := m.storage.GetWithContext(ctx, key)
if err != nil {
return nil, fmt.Errorf("csrf: failed to get value from storage: %w", err)
}
return raw, nil
}
if value := m.memory.Get(key); value != nil {
raw, ok := value.([]byte)
if !ok {
return nil, fmt.Errorf("csrf: unexpected value type %T in storage", value)
}
return raw, nil
}
return nil, nil
}
// set data to storage or memory
func (m *storageManager) setRaw(ctx context.Context, key string, raw []byte, exp time.Duration) error {
if m.storage != nil {
if err := m.storage.SetWithContext(ctx, key, raw, exp); err != nil {
return fmt.Errorf("csrf: failed to store key %q: %w", m.logKey(key), err)
}
return nil
}
m.memory.Set(key, raw, exp)
return nilView on GitHub (pinned to a105acad6c)