gofiber/fiber · error
failed to base64-decode value
Error message
failed to base64-decode value: %w
What it means
Returned by DecryptCookie when the incoming cookie value is not valid base64 (StdEncoding). DecryptCookie first base64-decodes the stored value before attempting AES-GCM decryption, so any non-base64 payload fails here. The wrapped %w carries encoding/base64's CorruptInputError, which reports the byte offset of corruption.
Solutions
- Verify the cookie was produced by EncryptCookie with the same base64 (StdEncoding) variant.
- Check for proxy/gateway re-encoding of cookie values (URL-encoding, stripping padding).
- If migrating encoding, clear/rotate old cookies so clients get fresh EncryptCookie output.
- Log the raw value length and the CorruptInputError offset to pinpoint corruption.
Example fix
// before
plaintext, err := encryptcookie.DecryptCookie(name, c.Cookies(name), key)
// after
raw := c.Cookies(name)
if _, bErr := base64.StdEncoding.DecodeString(raw); bErr != nil {
c.ClearCookie(name) // stale/tampered cookie; let the user re-auth
return c.Redirect("/login")
}
plaintext, err := encryptcookie.DecryptCookie(name, raw, key) Defensive patterns
Strategy: validation
Validate before calling
if _, err := base64.StdEncoding.DecodeString(value); err != nil {
// not a valid EncryptCookie payload; treat as missing
return redirectToLogin()
} Type guard
func isStdBase64(s string) bool {
_, err := base64.StdEncoding.DecodeString(s)
return err == nil
} Try / catch
plain, err := encryptcookie.DecryptCookie(name, value, key)
if err != nil {
c.ClearCookie(name)
return c.Redirect("/login")
} Prevention
- Always use EncryptCookie to produce values you later DecryptCookie.
- Keep the same base64 variant (StdEncoding) across all environments.
- On encoding migration, invalidate existing cookies.
When it happens
Trigger: Calling encryptcookie.DecryptCookie(name, value, key) where value is not a valid base64 string — e.g. a tampered cookie, a cookie set by a different library, a URL-safe base64 payload, or a value with whitespace/newlines that StdEncoding rejects.
Common situations: Switching from URLSafe base64 to standard base64 (or vice versa), clients truncating long cookies, proxies stripping '=' padding, rotating the encryption scheme without invalidating old cookies, or decrypting a plaintext cookie set by middleware that does not use EncryptCookie.
Related errors
- failed to base64-decode key
- decode SHA256 password
- decode SHA512 password
- encryption key must be 16, 24, or 32 bytes
- ErrEmptySessionID
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/af9178e2ba2161c3.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/encryptcookie/utils.go:70
gcm, err := cipher.NewGCMWithRandomNonce(block)
if err != nil {
return "", fmt.Errorf("failed to create GCM mode: %w", err)
}
ciphertext := gcm.Seal(nil, nil, []byte(value), []byte(name))
return base64.StdEncoding.EncodeToString(ciphertext), nil
}
// DecryptCookie Decrypts a cookie value with specific encryption key
func DecryptCookie(name, value, key string) (string, error) {
keyDecoded, err := decodeKey(key)
if err != nil {
return "", err
}
enc, err := base64.StdEncoding.DecodeString(value)
if err != nil {
return "", fmt.Errorf("failed to base64-decode value: %w", err)
}
block, err := aes.NewCipher(keyDecoded)
if err != nil {
return "", fmt.Errorf("failed to create AES cipher: %w", err)
}
gcm, err := cipher.NewGCMWithRandomNonce(block)
if err != nil {
return "", fmt.Errorf("failed to create GCM mode: %w", err)
}
if len(enc) < gcm.NonceSize()+gcm.Overhead() {
return "", ErrInvalidEncryptedValue
}
plaintext, err := gcm.Open(nil, nil, enc, []byte(name))
if err != nil {View on GitHub (pinned to a105acad6c)