gofiber/fiber · error
[session] AbsoluteTimeout must be greater than or equal to…
Error message
[session] AbsoluteTimeout must be greater than or equal to IdleTimeout
What it means
The session middleware enforces that AbsoluteTimeout (a hard cap on session lifetime) is at least as long as IdleTimeout (the inactivity window). An AbsoluteTimeout shorter than IdleTimeout is logically inconsistent — the session could never reach its idle window before being killed by the absolute cap — so configDefault panics. AbsoluteTimeout == 0 means "no absolute cap" and is explicitly allowed, so the panic only fires when AbsoluteTimeout is a positive value smaller than IdleTimeout.
Solutions
- Set AbsoluteTimeout >= IdleTimeout, or leave AbsoluteTimeout at 0 (no hard cap).
- If you need a short hard cap, lower IdleTimeout to match or fall below it.
- Centralize timeout values in named constants so both fields stay consistent.
Example fix
// before
session.New(session.Config{
IdleTimeout: 30 * time.Minute,
AbsoluteTimeout: 5 * time.Minute, // panics
})
// after
const (
sessionIdle = 30 * time.Minute
sessionAbsolute = 8 * time.Hour
)
session.New(session.Config{
IdleTimeout: sessionIdle,
AbsoluteTimeout: sessionAbsolute, // >= IdleTimeout, OK
}) Defensive patterns
Strategy: validation
Validate before calling
func validateSessionConfig(cfg session.Config) error {
idle := cfg.IdleTimeout
if idle <= 0 { idle = 30 * time.Minute } // mirrors configDefault
if cfg.AbsoluteTimeout > 0 && cfg.AbsoluteTimeout < idle {
return fmt.Errorf("AbsoluteTimeout (%s) < IdleTimeout (%s)", cfg.AbsoluteTimeout, idle)
}
return nil
}
// if err := validateSessionConfig(cfg); err != nil { log.Fatal(err) } Type guard
func sessionTimeoutsConsistent(cfg session.Config) bool {
idle := cfg.IdleTimeout
if idle <= 0 { idle = 30 * time.Minute }
return cfg.AbsoluteTimeout == 0 || cfg.AbsoluteTimeout >= idle
} Prevention
- Derive both timeouts from a small set of named constants so they cannot drift.
- Add a config-validation step in your bootstrap that runs before session.New.
- Watch for unit mismatches (time.Second vs time.Minute) when copying values between the two fields.
When it happens
Trigger: session.New(session.Config{IdleTimeout: 30 * time.Minute, AbsoluteTimeout: 5 * time.Minute}) — a 5-minute hard cap beneath a 30-minute idle window.
Common situations: Tuning session timeouts during security hardening; copy-pasting durations between the two fields; a unit mismatch (e.g. passing seconds to AbsoluteTimeout and minutes to IdleTimeout); shortening AbsoluteTimeout for compliance without also lowering IdleTimeout.
Understand the failure class
- Timeouts: ETIMEDOUT, deadlines, and hung requests — what actually expires when a request times out.
Related errors
- sse: Handler must not be nil
- add: invalid http method
- basicauth: charset must be UTF-8
- [CORS] Invalid origin format after normalization:
- [CORS] Invalid origin format in configuration:
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/fb7d1caf5992c486.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/session/config.go:147
// cfg := configDefault()
// cfg := configDefault(customConfig)
func configDefault(config ...Config) Config {
// Return default config if nothing provided
if len(config) < 1 {
return ConfigDefault
}
// Override default config
cfg := config[0]
// Set default values
if cfg.IdleTimeout <= 0 {
cfg.IdleTimeout = ConfigDefault.IdleTimeout
}
// Ensure AbsoluteTimeout is greater than or equal to IdleTimeout.
if cfg.AbsoluteTimeout > 0 && cfg.AbsoluteTimeout < cfg.IdleTimeout {
panic("[session] AbsoluteTimeout must be greater than or equal to IdleTimeout")
}
// Check if we have a zero-value Extractor
if cfg.Extractor.Extract == nil {
cfg.Extractor = ConfigDefault.Extractor
}
if cfg.KeyGenerator == nil {
cfg.KeyGenerator = ConfigDefault.KeyGenerator
}
if cfg.CookieSameSite == "" {
cfg.CookieSameSite = ConfigDefault.CookieSameSite
}
return cfg
}
View on GitHub (pinned to a105acad6c)