Skip to content

fix: prevent nil pointer dereference when store.New returns an error - #299

Closed
AdamMagued wants to merge 1 commit into
gorilla:mainfrom
AdamMagued:fix-store-new-nil-session-panic
Closed

AdamMagued wants to merge 1 commit into
gorilla:mainfrom
AdamMagued:fix-store-new-nil-session-panic

Conversation

@AdamMagued

Copy link
Copy Markdown

Fixes #288

Problem

When a custom Store implementation returns an error and a nil *Session from New(r, name), Registry.Get attempts to dereference session.name, causing a runtime nil pointer dereference panic.

Solution

  • In Registry.Get, check if session is nil after store.New. If session is nil, return (nil, err) directly without attempting to set session properties or caching a nil session in the registry.
  • Add regression test TestRegistryGetStoreNewError in sessions_test.go verifying that Registry.Get returns the error without panicking when store.New returns a nil session and an error, and verifying that subsequent Save and Get calls complete safely.

When a custom Store implementation encounters an error in New and returns a nil Session alongside the error, Registry.Get attempted to dereference session.name without checking if session was nil, leading to a panic.

Check if session is nil after store.New and return (nil, err) directly to prevent panics and avoid storing a nil session in the registry.

Fixes gorilla#288
@AdamMagued

Copy link
Copy Markdown
Author

Closing in favor of earlier community PRs to keep the review queue clean.

@AdamMagued AdamMagued closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Panic if store.New returns an error

1 participant