gofiber/fiber · critical
fiber: encrypt cookie middleware requires key
Error message
fiber: encrypt cookie middleware requires key
What it means
The encryptcookie middleware requires a symmetric AES key to encrypt/decrypt cookie values; an empty Config.Key provides no security and is rejected at startup with panic. The empty-key check runs after defaulting Encryptor/Decryptor but before validateKey, so an empty key fails fast with a clear message rather than a downstream AES error.
Solutions
- Provision a key with encryptcookie.GenerateKey(32) and pass it: Config{ Key: key }.
- Load the key from a secret store/env var and fail loudly at boot if it is empty: key := os.Getenv("COOKIE_KEY"); if key == "" { log.Fatal(...) }.
- Ensure the same key is distributed to every instance that must read the encrypted cookies (key rotation requires dual-key handling).
Example fix
// before
app.Use(encryptcookie.New(encryptcookie.Config{}))
// after
key := os.Getenv("COOKIE_KEY")
if key == "" { log.Fatal("COOKIE_KEY not set") }
app.Use(encryptcookie.New(encryptcookie.Config{ Key: key })) Defensive patterns
Strategy: validation
Validate before calling
key := os.Getenv("COOKIE_KEY")
if key == "" {
log.Fatal("COOKIE_KEY is not set; generate one with encryptcookie.GenerateKey(32)")
}
// optional: validate decode length up front
if err := encryptcookie.GenerateKey /* unused */; false {
}
app.Use(encryptcookie.New(encryptcookie.Config{ Key: key })) Try / catch
defer func() {
if r := recover(); r != nil {
log.Fatalf("encryptcookie key missing/invalid: %v", r)
}
}()
app.Use(encryptcookie.New(cfg)) Prevention
- Provision the key in a secret manager; never commit it.
- Fail fast at boot if the key env var is empty.
- Distribute the same key to all instances sharing the cookies; plan key rotation explicitly.
When it happens
Trigger: encryptcookie.New(encryptcookie.Config{ /* Key omitted */ }) or encryptcookie.New(encryptcookie.Config{ Key: "" }) — typically because the key was meant to be loaded from an environment variable or secret store that resolved to empty (unset env var, wrong key name, missing file).
Common situations: Forgetting to set the COOKIE_KEY env var; typo in the env var name in os.Getenv; secret not mounted in a container/Kubernetes deployment; running a new environment (CI, staging) without provisioning the key; reading the key from a config file that was git-ignored and is absent.
Related errors
- [CORS] Invalid origin format in configuration:
- [CSRF] Invalid origin format in configuration:
- basicauth: charset must be UTF-8
- [CORS] Configuration error: When 'AllowCredentials' is set…
- [CORS] Invalid origin format after normalization:
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/24ac6a0db0c92139.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/encryptcookie/config.go:74
if cfg.Next == nil {
cfg.Next = ConfigDefault.Next
}
if cfg.Except == nil {
cfg.Except = ConfigDefault.Except
}
if cfg.Encryptor == nil {
cfg.Encryptor = ConfigDefault.Encryptor
}
if cfg.Decryptor == nil {
cfg.Decryptor = ConfigDefault.Decryptor
}
}
if cfg.Key == "" {
panic("fiber: encrypt cookie middleware requires key")
}
if err := validateKey(cfg.Key); err != nil {
panic(err)
}
return cfg
}
View on GitHub (pinned to a105acad6c)