gofiber/fiber · error
failed to create GCM mode
Error message
failed to create GCM mode: %w
What it means
Returned by EncryptCookie when cipher.NewGCMWithRandomNonce fails after the AES block cipher was created. The Go stdlib only errors here if the block size is unsupported; AES blocks are always 128-bit so this branch is effectively unreachable for valid AES keys. Because decodeKey already enforces 16/24/32-byte lengths, hitting it implies an unexpected crypto/cipher runtime state or a corrupted binary.
Solutions
- Confirm the error is not actually from decodeKey or aes.NewCipher (read the wrapped %w chain) — those are the real-world causes.
- Ensure you are using the unmodified Go standard library crypto/aes (no vendored forks).
- Regenerate the key with encryptcookie.GenerateKey(32) to rule out key-shape corruption.
- If genuinely hit, file a Go stdlib issue; this branch is not actionable from application code.
Example fix
// before
key := "some-hardcoded-value"
enc, err := encryptcookie.EncryptCookie(name, value, key)
// after
key := encryptcookie.GenerateKey(32) // valid base64 AES-256 key
enc, err := encryptcookie.EncryptCookie(name, value, key)
if err != nil {
return fmt.Errorf("encrypt cookie: %w", err)
} Defensive patterns
Strategy: try-catch
Validate before calling
if err := encryptcookie.KeyValidator(key); err != nil { return fmt.Errorf("boot: %w", err) } Try / catch
enc, err := encryptcookie.EncryptCookie(name, value, key)
if err != nil {
if errors.Is(err, cipher.NewGCMWithRandomNonceError) { /* unreachable in practice */ }
return fmt.Errorf("encrypt cookie: %w", err)
} Prevention
- Generate keys with encryptcookie.GenerateKey(16|24|32) at deploy time.
- Validate the key once at startup via KeyValidator.
- Never fork crypto/aes; rely on the Go standard library.
When it happens
Trigger: Calling encryptcookie.EncryptCookie(name, value, key) with a key that passed base64+length validation but for which cipher.NewGCMWithRandomNonce(block) returns a non-nil error. In practice this never fires with stdlib AES; it would only surface if a custom/modified aes.NewCipher returned a block with a non-standard block size.
Common situations: Developers see this only as a defensive guard. It can appear after swapping the stdlib crypto/aes for a faulty fork, on exotic GOOS/GOARCH builds with broken crypto assembly, or when fuzzing the cipher layer. Standard deployments never encounter it.
Related errors
- failed to decrypt ciphertext
- encryption key must be 16, 24, or 32 bytes
- failed to base64-decode key
- failed to create AES cipher
- decode SHA256 password: invalid length
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/a1c9bb2c10b7a694.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/encryptcookie/utils.go:54
_, err := decodeKey(key)
return err
}
// EncryptCookie Encrypts a cookie value with specific encryption key
func EncryptCookie(name, value, key string) (string, error) {
keyDecoded, err := decodeKey(key)
if err != nil {
return "", err
}
block, err := aes.NewCipher(keyDecoded)
if err != nil {
return "", fmt.Errorf("failed to create AES cipher: %w", err)
}
gcm, err := cipher.NewGCMWithRandomNonce(block)
if err != nil {
return "", fmt.Errorf("failed to create GCM mode: %w", err)
}
ciphertext := gcm.Seal(nil, nil, []byte(value), []byte(name))
return base64.StdEncoding.EncodeToString(ciphertext), nil
}
// DecryptCookie Decrypts a cookie value with specific encryption key
func DecryptCookie(name, value, key string) (string, error) {
keyDecoded, err := decodeKey(key)
if err != nil {
return "", err
}
enc, err := base64.StdEncoding.DecodeString(value)
if err != nil {
return "", fmt.Errorf("failed to base64-decode value: %w", err)
}
View on GitHub (pinned to a105acad6c)