gofiber/fiber · error
fiber: keyauth scope contains invalid token
Error message
fiber: keyauth scope contains invalid token
What it means
When Error is insufficient_scope, keyauth splits Config.Scope on spaces and validates each token with isScopeToken, which permits printable ASCII (0x21–0x7e) except double-quote and backslash. Any token that is empty, contains a control char, a quote, or a backslash panics, because these would break the RFC 6750 scope parameter serialization in the WWW-Authenticate header (log injection / header-injection safe).
Solutions
- Use simple alphanumeric scope tokens: "read write admin".
- Trim and de-duplicate spaces before assigning Scope (e.g. strings.Join(strings.Fields(s), " ")).
- Reject scope names containing characters outside [A-Za-z0-9-_] at the source rather than relying on the middleware panic.
Example fix
// before
app.Use(keyauth.New(keyauth.Config{
Validator: v,
Error: keyauth.ErrorInsufficientScope,
Scope: "read \"admin\"",
}))
// after
app.Use(keyauth.New(keyauth.Config{
Validator: v,
Error: keyauth.ErrorInsufficientScope,
Scope: "read admin",
})) Defensive patterns
Strategy: validation
Validate before calling
func sanitizeScope(s string) (string, error) {
fields := strings.Fields(s) // collapses repeated spaces, drops empties
for _, f := range fields {
for i := 0; i < len(f); i++ {
c := f[i]
if c < 0x21 || c > 0x7e || c == '"' || c == '\\' {
return "", fmt.Errorf("invalid scope token %q", f)
}
}
}
return strings.Join(fields, " "), nil
} Prevention
- Restrict scope tokens to [A-Za-z0-9_-] at the source.
- Normalize with strings.Fields to eliminate empty/whitespace tokens before assignment.
- Never interpolate raw user input into Scope.
When it happens
Trigger: Scope: "read \"admin\"" (contains quotes), "read\nwrite" (newline, also a CRLF-injection risk), "read write" (double space yields an empty token), or a scope containing a non-ASCII character.
Common situations: User-supplied scope names concatenated without sanitization; copy-pasting scopes from JSON where quotes were not stripped; trailing space producing an empty trailing token.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- fiber: keyauth insufficient_scope requires scope
- fiber: keyauth scope requires insufficient_scope error
- fiber: keyauth error_description requires error
- fiber: keyauth error_uri must be absolute
- fiber: keyauth error_uri requires error
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/5683829ed6a994d3.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/keyauth/config.go:156
}
if cfg.ErrorDescription != "" && cfg.Error == "" {
panic("fiber: keyauth error_description requires error")
}
if cfg.ErrorURI != "" {
if cfg.Error == "" {
panic("fiber: keyauth error_uri requires error")
}
if u, err := url.Parse(cfg.ErrorURI); err != nil || !u.IsAbs() {
panic("fiber: keyauth error_uri must be absolute")
}
}
if cfg.Error == ErrorInsufficientScope {
if cfg.Scope == "" {
panic("fiber: keyauth insufficient_scope requires scope")
}
for scope := range strings.SplitSeq(cfg.Scope, " ") {
if scope == "" || !isScopeToken(scope) {
panic("fiber: keyauth scope contains invalid token")
}
}
} else if cfg.Scope != "" {
panic("fiber: keyauth scope requires insufficient_scope error")
}
return cfg
}
func isScopeToken(s string) bool {
for i := 0; i < len(s); i++ {
c := s[i]
if c < 0x21 || c > 0x7e || c == '"' || c == '\\' {
return false
}
}
return s != ""
}View on GitHub (pinned to a105acad6c)