gofiber/fiber · error
fiber: keyauth middleware requires a validator function
Error message
fiber: keyauth middleware requires a validator function
What it means
keyauth.New() panics when called with no Config argument at all. Because Validator is the only required field and cannot have a sensible default, calling New() with zero arguments is treated as a programmer error: the middleware has no way to decide which keys are valid. The same message is reused for the nil-Validator case (error 287) but this specific line fires on len(config) < 1.
Solutions
- Pass a Config with a Validator: keyauth.New(keyauth.Config{Validator: func(c fiber.Ctx, key string) (bool, error){ ... }}).
- If you are just scaffolding, comment out the app.Use(keyauth.New()) line until the Validator is ready.
- Ensure any helper that builds keyauth config always returns a non-nil Validator before the result reaches New().
Example fix
// before
app.Use(keyauth.New())
// after
app.Use(keyauth.New(keyauth.Config{
Validator: func(_ fiber.Ctx, key string) (bool, error) {
return key == os.Getenv("API_KEY"), nil
},
})) Defensive patterns
Strategy: validation
Validate before calling
func mustKeyAuth(validator func(fiber.Ctx, string) (bool, error)) fiber.Handler {
if validator == nil {
log.Fatal("keyauth requires a validator")
}
return keyauth.New(keyauth.Config{Validator: validator})
} Type guard
func hasKeyAuthConfig(args ...keyauth.Config) bool { return len(args) > 0 } Prevention
- Never call keyauth.New() without arguments in production code paths.
- Wrap keyauth.New in a project helper that always supplies a Validator.
- Add a smoke test that boots the app to catch missing-config panics in CI.
When it happens
Trigger: keyauth.New() with no arguments. Also any wrapper that does var cfg keyauth.Config; keyauth.New(cfg) would NOT hit this line (it has len 1) — only a truly empty variadic call does.
Common situations: Adding app.Use(keyauth.New()) as a placeholder during scaffolding and forgetting to come back; refactor that moves Config construction into a function returning zero values; conditional wiring where the config-arg branch is dropped.
Related errors
- fiber: keyauth error_description requires error
- fiber: keyauth error_uri must be absolute
- fiber: keyauth error_uri requires error
- fiber: keyauth insufficient_scope requires scope
- fiber: keyauth scope contains invalid token
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/7b7ccc353cce8004.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/keyauth/config.go:105
}
// ConfigDefault is the default config
var ConfigDefault = Config{
SuccessHandler: func(c fiber.Ctx) error {
return c.Next()
},
ErrorHandler: func(c fiber.Ctx, _ error) error {
return c.Status(fiber.StatusUnauthorized).SendString(ErrMissingOrMalformedAPIKey.Error())
},
Realm: "Restricted",
Extractor: extractors.FromAuthHeader("Bearer"),
}
// configDefault is a helper function to set default values
func configDefault(config ...Config) Config {
// Return default config if nothing provided
if len(config) < 1 {
panic("fiber: keyauth middleware requires a validator function")
}
cfg := config[0]
// Require a validator function
if cfg.Validator == nil {
panic("fiber: keyauth middleware requires a validator function")
}
// Set default values
if cfg.Extractor.Extract == nil {
cfg.Extractor = ConfigDefault.Extractor
}
if cfg.Realm == "" {
cfg.Realm = ConfigDefault.Realm
}
if cfg.SuccessHandler == nil {
cfg.SuccessHandler = ConfigDefault.SuccessHandler
}View on GitHub (pinned to a105acad6c)