gofiber/fiber · error
failed to create AES cipher
Error message
failed to create AES cipher: %w
What it means
Returned by EncryptCookie (and DecryptCookie) when aes.NewCipher fails on the decoded key. Because decodeKey already validated the length to be 16/24/32 bytes, aes.NewCipher should not fail in practice — it can only fail on a non-positive key length, which the prior guard excludes. Encountering it indicates an unexpected crypto/library state or a key whose length validation was bypassed.
Solutions
- Confirm the key reaches EncryptCookie via the public API and decodeKey (which enforces length) — do not call aes.NewCipher directly with user input.
- Regenerate the key with GenerateKey to rule out malformed key material.
- Rebuild with a stock Go toolchain to rule out a corrupted crypto/aes.
- Treat as a bug if reproduced with a valid 16/24/32-byte key through the public API.
Defensive patterns
Strategy: validation
Validate before calling
// Validate the key material end-to-end at startup by performing a roundtrip.
func validateKeyRoundtrip(key string) error {
enc, err := encryptcookie.EncryptCookie("probe", "v", key)
if err != nil {
return fmt.Errorf("encrypt roundtrip failed: %w", err)
}
if _, err := encryptcookie.DecryptCookie("probe", enc, key); err != nil {
return fmt.Errorf("decrypt roundtrip failed: %w", err)
}
return nil
} Try / catch
// Practically unreachable; guard at the boundary by validating the key once
// at boot rather than per request.
if err := validateKeyRoundtrip(cfg.Key); err != nil {
log.Fatal("encryptcookie key invalid:", err)
} Prevention
- Route keys through decodeKey (via the public API) so length is validated before aes.NewCipher.
- Generate keys with GenerateKey; do not construct key bytes manually.
- Run a startup roundtrip probe to catch any toolchain/crypto anomaly early.
When it happens
Trigger: Only reachable if aes.NewCipher returns an error for a key that decodeKey accepted — i.e. effectively unreachable under the documented contract. Hypothetically: a malformed build, a forked/patched decodeKey that skipped length validation, or a corrupted crypto/aes package.
Common situations: Not encountered in normal operation. If seen, suspect a code path that calls aes.NewCipher with an unvalidated key (bypassing decodeKey), or an exotic platform/toolchain issue. Treat as a defense-in-depth guard rather than an operational error.
Related errors
- failed to base64-decode key
- cache: unexpected entry type %T for key
- cache: unexpected raw entry type %T for key
- csrf: unexpected value type %T in storage
- cache: failed to delete key
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/6bb342649d1f142b.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/encryptcookie/utils.go:49
return keyDecoded, nil
}
// validateKey checks if the provided base64-encoded key is of valid length.
func validateKey(key string) error {
_, err := decodeKey(key)
return err
}
// EncryptCookie Encrypts a cookie value with specific encryption key
func EncryptCookie(name, value, key string) (string, error) {
keyDecoded, err := decodeKey(key)
if err != nil {
return "", err
}
block, err := aes.NewCipher(keyDecoded)
if err != nil {
return "", fmt.Errorf("failed to create AES cipher: %w", err)
}
gcm, err := cipher.NewGCMWithRandomNonce(block)
if err != nil {
return "", fmt.Errorf("failed to create GCM mode: %w", err)
}
ciphertext := gcm.Seal(nil, nil, []byte(value), []byte(name))
return base64.StdEncoding.EncodeToString(ciphertext), nil
}
// DecryptCookie Decrypts a cookie value with specific encryption key
func DecryptCookie(name, value, key string) (string, error) {
keyDecoded, err := decodeKey(key)
if err != nil {
return "", err
}
View on GitHub (pinned to a105acad6c)