gofiber/fiber · error

fiber: keyauth error_uri requires error

Error message

fiber: keyauth error_uri requires error

What it means

Like error_description, RFC 6750's error_uri parameter is meaningful only when paired with an error code. keyauth panics when Config.ErrorURI is set but Config.Error is empty. error_uri is meant to give a link explaining the error, so it cannot stand alone in a challenge.

Solutions

  1. Set Config.Error to a valid code (e.g. keyauth.ErrorInvalidToken) whenever ErrorURI is set.
  2. Drop ErrorURI if no Error is configured.
  3. Enforce the dependency in your config loader: ErrorURI requires Error.

Example fix

// before
app.Use(keyauth.New(keyauth.Config{
    Validator: v,
    ErrorURI:  "https://docs.example.com/auth",
}))

// after
app.Use(keyauth.New(keyauth.Config{
    Validator: v,
    Error:     keyauth.ErrorInvalidToken,
    ErrorURI:  "https://docs.example.com/auth",
}))
Defensive patterns

Strategy: validation

Validate before calling

if cfg.ErrorURI != "" && cfg.Error == "" {
    log.Fatal("keyauth: ErrorURI requires Error")
}

Prevention

When it happens

Trigger: keyauth.Config{ErrorURI: "https://example.com/errors"} with Error unset. Reached when ErrorURI is configured globally but Error is wired per-endpoint and missing on this instance.

Common situations: Setting a documentation link as ErrorURI by default but forgetting to set the Error code that triggers it; splitting error fields across config files that desync.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/aefc9be827b6ae83. Report an issue: GitHub.

Appendix: source

Thrown at middleware/keyauth/config.go:144

	}

	if len(getAuthSchemes(cfg.Extractor)) == 0 && cfg.Challenge == "" {
		cfg.Challenge = fmt.Sprintf("ApiKey realm=%q", cfg.Realm)
	}

	if cfg.Error != "" {
		switch cfg.Error {
		case ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope:
		default:
			panic("fiber: keyauth unsupported error token")
		}
	}
	if cfg.ErrorDescription != "" && cfg.Error == "" {
		panic("fiber: keyauth error_description requires error")
	}
	if cfg.ErrorURI != "" {
		if cfg.Error == "" {
			panic("fiber: keyauth error_uri requires error")
		}
		if u, err := url.Parse(cfg.ErrorURI); err != nil || !u.IsAbs() {
			panic("fiber: keyauth error_uri must be absolute")
		}
	}
	if cfg.Error == ErrorInsufficientScope {
		if cfg.Scope == "" {
			panic("fiber: keyauth insufficient_scope requires scope")
		}
		for scope := range strings.SplitSeq(cfg.Scope, " ") {
			if scope == "" || !isScopeToken(scope) {
				panic("fiber: keyauth scope contains invalid token")
			}
		}
	} else if cfg.Scope != "" {
		panic("fiber: keyauth scope requires insufficient_scope error")
	}

View on GitHub (pinned to a105acad6c)