gofiber/fiber · error

fiber: keyauth scope contains invalid token

Error message

fiber: keyauth scope contains invalid token

What it means

When Error is insufficient_scope, keyauth splits Config.Scope on spaces and validates each token with isScopeToken, which permits printable ASCII (0x21–0x7e) except double-quote and backslash. Any token that is empty, contains a control char, a quote, or a backslash panics, because these would break the RFC 6750 scope parameter serialization in the WWW-Authenticate header (log injection / header-injection safe).

Solutions

  1. Use simple alphanumeric scope tokens: "read write admin".
  2. Trim and de-duplicate spaces before assigning Scope (e.g. strings.Join(strings.Fields(s), " ")).
  3. Reject scope names containing characters outside [A-Za-z0-9-_] at the source rather than relying on the middleware panic.

Example fix

// before
app.Use(keyauth.New(keyauth.Config{
    Validator: v,
    Error:     keyauth.ErrorInsufficientScope,
    Scope:     "read \"admin\"",
}))

// after
app.Use(keyauth.New(keyauth.Config{
    Validator: v,
    Error:     keyauth.ErrorInsufficientScope,
    Scope:     "read admin",
}))
Defensive patterns

Strategy: validation

Validate before calling

func sanitizeScope(s string) (string, error) {
    fields := strings.Fields(s) // collapses repeated spaces, drops empties
    for _, f := range fields {
        for i := 0; i < len(f); i++ {
            c := f[i]
            if c < 0x21 || c > 0x7e || c == '"' || c == '\\' {
                return "", fmt.Errorf("invalid scope token %q", f)
            }
        }
    }
    return strings.Join(fields, " "), nil
}

Prevention

When it happens

Trigger: Scope: "read \"admin\"" (contains quotes), "read\nwrite" (newline, also a CRLF-injection risk), "read write" (double space yields an empty token), or a scope containing a non-ASCII character.

Common situations: User-supplied scope names concatenated without sanitization; copy-pasting scopes from JSON where quotes were not stripped; trailing space producing an empty trailing token.

Understand the failure class

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/5683829ed6a994d3. Report an issue: GitHub.

Appendix: source

Thrown at middleware/keyauth/config.go:156

	}
	if cfg.ErrorDescription != "" && cfg.Error == "" {
		panic("fiber: keyauth error_description requires error")
	}
	if cfg.ErrorURI != "" {
		if cfg.Error == "" {
			panic("fiber: keyauth error_uri requires error")
		}
		if u, err := url.Parse(cfg.ErrorURI); err != nil || !u.IsAbs() {
			panic("fiber: keyauth error_uri must be absolute")
		}
	}
	if cfg.Error == ErrorInsufficientScope {
		if cfg.Scope == "" {
			panic("fiber: keyauth insufficient_scope requires scope")
		}
		for scope := range strings.SplitSeq(cfg.Scope, " ") {
			if scope == "" || !isScopeToken(scope) {
				panic("fiber: keyauth scope contains invalid token")
			}
		}
	} else if cfg.Scope != "" {
		panic("fiber: keyauth scope requires insufficient_scope error")
	}

	return cfg
}

func isScopeToken(s string) bool {
	for i := 0; i < len(s); i++ {
		c := s[i]
		if c < 0x21 || c > 0x7e || c == '"' || c == '\\' {
			return false
		}
	}
	return s != ""
}

View on GitHub (pinned to a105acad6c)